Hardware Configuration Reporting via Trusted Execution Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual configuration of hardware configuration registers during boot-up is prone to errors, which can lead to security risks as malicious code can exploit open settings, potentially affecting system performance.

Innovation Solution

A hardware configuration reporting system that includes a trusted execution environment (TEE) and non-TEE, with arbiter logic and reporting logic to detect and report register values, enabling secure detection of errors and mitigation of security risks through automated actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual configuration of hardware configuration registers is performed, then configuration flexibility is improved, but configuration accuracy deteriorates due to human error

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidconfiguration accuracy
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The system performs self-verification by automatically reading back the configured register values and comparing them against the intended configuration. This self-service mechanism eliminates human error in verification while preserving manual configuration flexibility, as the system checks its own work without requiring human intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements a feedback loop where the configured register values are read back and compared with the intended values. This feedback mechanism provides immediate verification of configuration accuracy, allowing the system to detect and report errors automatically while maintaining the flexibility of manual configuration.

Inventive Principle:
Principle #23Feedback

2Manufacturing precision

If automated detection and reporting of register values is implemented, then configuration accuracy is improved, but device complexity increases

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidsystem complexity
Core Design Contradiction:
Manufacturing precisionVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary verification layer that sits between the configuration process and the hardware registers. This intermediary component handles the complex tasks of reading, comparing, and reporting register values, thereby improving configuration accuracy while encapsulating the complexity in a manageable verification module.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary verification actions by checking register values immediately after configuration. This preliminary action ensures configuration accuracy is verified before the system proceeds, preventing error propagation while keeping the complexity contained within the verification step.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If security policies are enforced through automated arbitration, then system security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The arbitration logic performs self-service security verification by automatically checking configuration values against predefined security policies. This eliminates the need for manual security checks, improving system security while maintaining operational simplicity as the system handles security verification autonomously without requiring user expertise.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3161710B1Hardware configuration reporting systems
Publication Date: 2019.12.04 INTEL CORP
  • EP3161710B1 patent drawingFigure 1~2
  • EP3161710B1 patent drawingFigure 3~4
  • EP3161710B1 patent drawingFigure 5~6

AI summary

Embodiments related to hardware configuration reporting and arbitration are disclosed herein. For example, an apparatus for hardware configuration reporting may include: a processing device having a trusted execution environment (TEE) and a non-trusted execution environment (non-TEE); request service logic, stored in the memory, to operate within the TEE to receive an indication of a request from arbiter logic, wherein the request represents a hardware configuration register; and reporting logic, stored in the memory, to operate within the TEE and to report an indicator of a value of the hardware configuration register represented by the request to the arbiter logic. Other embodiments may be disclosed and/or claimed.