Enclave Memory Region Secure Device Address Map
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing trusted execution environments face performance and battery-life issues due to the time- and power-consuming encryption and decryption processes required for secure communication with hardware devices, particularly in mobile systems.
Innovation Solution
Implementing an enclave memory region with a secure access control model that uses a device enclave mode bit to enable direct memory access and memory-mapped I/O communications without the need for encryption, allowing secure communication between the enclave and devices through a secure device address map and register filter component.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and decryption are used for secure communication between enclave and hardware devices, then security is maintained, but performance and battery life deteriorate
Solution Approach 1:
The patent segments the communication path into two distinct channels: an encrypted channel for general data communication and a secure unencrypted channel for time-sensitive operations. The secure device address map creates a dedicated memory region that bypasses encryption, while the device enclave mode bit identifies which channel to use. This segmentation allows critical performance operations to avoid encryption overhead while maintaining security for other communications.
Solution Approach 2:
The patent introduces an intermediary mechanism—the secure device address map and device enclave mode bit—that mediates between the enclave and hardware devices. This intermediary enables direct memory access for time-sensitive operations without requiring encryption/decryption, thus resolving the contradiction by providing a trusted shortcut path while maintaining overall security through the mode bit verification.
2Reliability
If encryption and decryption are used for secure communication between enclave and hardware devices, then security is maintained, but energy consumption increases
Solution Approach 1:
The communication system is segmented into encrypted and unencrypted paths based on operational requirements. Time-sensitive operations use the unencrypted path through the secure device address map, consuming minimal energy, while other operations use the encrypted path. The device enclave mode bit determines which path to take, enabling energy-efficient operation for critical functions without compromising overall security.
Solution Approach 2:
The patent changes the encryption parameter dynamically based on the device enclave mode bit. When the mode bit indicates a time-sensitive operation, encryption is disabled for that transaction, reducing energy consumption. This parameter change allows the system to adapt energy usage to operational requirements, extending battery life while maintaining security for non-time-critical operations.
3Productivity
If direct memory access is enabled for devices to communicate with enclave, then communication efficiency improves, but security risks increase
Solution Approach 1:
The patent applies local quality by creating a secure device address map that maps only specific device addresses to enclave memory regions. This localized address mapping ensures that direct memory access is permitted only for authorized device-enclave communication paths, while other access attempts are blocked. The device enclave mode bit further refines this local quality by identifying authorized transactions at the bit level, maintaining security while enabling efficient direct access where needed.
Data Source
AI summary
Various embodiments are generally directed to an apparatus, method, and other techniques to provide direct-memory access, memory-mapped input-output, and/or other memory transactions between devices designated for use by an enclave and the enclave itself. A secure device address map may be configured to map addresses for the enslave device and the enclave, and a register filter component may grant access to the enclave device to the enclave.


