Heterogeneous Trusted Execution Environment With Mutual Integrity Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional confidential computing in heterogeneous computing architectures, involving CPUs and accelerators, faces challenges in covering comprehensive computing scenarios due to the need for separate security isolation entities and data transmission, which is not adequately addressed by existing technologies.

Innovation Solution

A method for creating a heterogeneous trusted execution environment where both the CPU and the accelerator perform integrity measurements on each other's security isolation entities, establish access control policies, and engage in key agreement to encrypt and decrypt confidential data, allowing flexible creation of security isolation entities among multiple processors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate security isolation entities are created by CPU and accelerator, then security isolation is achieved, but system complexity increases and comprehensive computing scenarios are not covered

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security isolation entity creation process into a unified operation where the CPU and accelerator create security isolation entities simultaneously based on a unified request, rather than separately. This is achieved through the first processor creating a first security isolation entity and sending a creation request to the second processor, which then creates a second security isolation entity in response, enabling coordinated security isolation across heterogeneous computing devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements universality by enabling both the CPU and accelerator to perform integrity measurement on each other's security isolation entities, and by allowing either processor to initiate the creation of security isolation entities. This multi-functional capability ensures that comprehensive computing scenarios can be covered regardless of which processor provides confidential data or performs the computing task.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of operation

If CPU provides data and accelerator creates security isolation entity, then data transmission is enabled, but adaptability to comprehensive computing scenarios is limited

Engineering Contradiction:
Improvedata transmissionVSAvoidcomputing scenario coverage
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies inversion by allowing the accelerator to perform integrity measurement on the CPU's security isolation entity, and by enabling the CPU to create security isolation entities that can access the accelerator's entities through access control policies. This bidirectional capability ensures adaptability whether the CPU or accelerator provides confidential data, covering comprehensive computing scenarios.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent implements feedback through the access control policy mechanism where the first processor sets policies that define access permissions between security isolation entities of different processors. The second processor's security isolation entity can access the first processor's entity if permitted, enabling flexible adaptation to various computing scenarios where either processor may need to access data from the other.

Inventive Principle:
Principle #23Feedback

3Ease of manufacture

If integrity measurement is performed unidirectionally, then measurement process is simple, but comprehensive computing scenarios cannot be covered

Engineering Contradiction:
Improvemeasurement process simplicityVSAvoidcomputing scenario coverage
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent applies asymmetry in the sense that while both processors perform integrity measurement, the measurement process is asymmetric in its bidirectional nature - the first processor measures the second processor's security isolation entity and vice versa. This asymmetric mutual measurement ensures that both processors can verify the integrity of entities created by the other, enabling comprehensive computing scenarios where either processor may provide confidential data.

Inventive Principle:
Principle #4Asymmetry

Data Source

PatentUS20250300817A1Method for creating heterogeneous trusted execution environment, apparatus, and computing system
Publication Date: 2025.09.25 HUAWEI TECH CO LTD
  • US20250300817A1 patent drawing
  • US20250300817A1 patent drawing
  • US20250300817A1 patent drawing

AI summary

A method for creating a heterogeneous trusted execution environment, an apparatus, and a computing system are provided, and relate to the field of computer technologies. In an implementation, the method is applied to a computing device including a first processor and a second processor that are heterogeneous. The first processor creates a first security isolation entity based on a computing resource of the first processor; the first processor sends a first creation request to the second processor; the second processor creates a second security isolation entity based on a computing resource of the second processor in response to the first creation request; the first processor performs integrity measurement on the second security isolation entity on a side of the second processor; and the second processor performs integrity measurement on the first security isolation entity on a side of the first processor.