HRoT Agent Isolation in Secure Virtualization for TEE Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing processor-based trusted execution environments (TEEs) have low security and cannot perform high-security operations due to their reliance on a trusted execution environment operating system, leading to a large code scale, increased attack surface, and high costs for deployment and authentication.

Innovation Solution

Implement a hardware root of trust (HRoT) agent interaction method based on secure virtualization, where the HRoT agent and driver are constructed as independent trusted execution environment programs managed by a TEE manager, isolating them from the TEE operating system, and using a lightweight TEE manager for permission control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing processor-based TEE system architecture is used, then security operations can be performed, but the security level is low and cannot handle high-security operations due to large code scale and increased attack surface

Engineering Contradiction:
Improvesecurity levelVSAvoidcode scale
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the HRoT agent and driver from the TEE operating system environment, creating independent TEE programs that directly interact with the hardware root of trust. This extraction eliminates the need for a full TEE OS, reducing code scale while maintaining high security operations capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the security system into distinct components: the TEE manager (in normal world), HRoT agent TEE program (in secure world), and HRoT driver TEE program (in secure world). This segmentation isolates security-critical code from the general TEE OS, reducing the attack surface while enabling high-security operations.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If TEE operating system is used to manage HRoT agent, then functionality is provided, but deployment costs increase and flexibility decreases due to binding requirements

Engineering Contradiction:
Improvedeployment flexibilityVSAvoiddeployment cost
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the HRoT agent and driver from the TEE operating system, allowing them to be deployed as independent TEE programs. This eliminates the binding requirement with a specific TEE OS version, increasing deployment flexibility and reducing authentication costs.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The TEE manager provides universal management functionality for multiple HRoT agent TEE programs without requiring each program to be bound to a specific TEE OS. This multi-functional approach reduces deployment complexity and costs while maintaining flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260010618A1Hardware root of trust agent interaction method based on secure virtualization and network device
Publication Date: 2026.01.08 HUAWEI TECH CO LTD
  • US20260010618A1 patent drawing
  • US20260010618A1 patent drawing
  • US20260010618A1 patent drawing

AI summary

A network device including a main service processor and a hardware root of trust. The main service processor includes a hardware root of trust agent program, a hardware root of trust driver program, and a trusted execution environment manager. The hardware root of trust agent is managed by the trusted execution environment manager. After receiving an invoking request instruction of the hardware root of trust, the hardware root of trust agent generates an invoking request instruction that is of the hardware root of trust and that is identifiable by the hardware root of trust driver.