Hybrid TEE Device Cache Purging Controller Memory Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trusted execution environments (TEEs) are vulnerable to malicious code execution due to inadequate memory isolation, cache manipulation, and information leakage issues, such as the 'Rowhammer' vulnerability.

Innovation Solution

A Hybrid TEE device is implemented using hardware elements like a Cache Purging Controller (CPC), Memory Isolation Gateway (MIG), and Memory Clean Up (MCU) in conjunction with TEE-enabled System software to enhance security and prevent malicious code execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional TEE memory isolation is used, then code execution security is improved, but memory isolation adequacy deteriorates due to cache leakage and resource sharing

Engineering Contradiction:
Improvecode execution securityVSAvoidmemory isolation adequacy
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the memory architecture into separate secure and non-secure memory spaces with dedicated isolation gateways. The secure memory region is physically separated from non-secure memory, and access between them is controlled through isolation gateways that enforce strict access control policies, preventing cache leakage and resource sharing vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces isolation gateways as intermediary components between secure and non-secure memory regions. These gateways act as mediators that control and monitor all memory access transitions, ensuring that only authorized access is permitted while blocking unauthorized access attempts, thereby resolving the memory isolation adequacy issue.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If functional module switching from secure world to normal world is implemented, then application flexibility is improved, but switching vulnerability increases

Engineering Contradiction:
Improveapplication flexibilityVSAvoidswitching vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary security checks and validation procedures before allowing switching from the secure world to the normal world. The system performs verification of access rights, validates memory addresses, and ensures security policies are met prior to enabling the functional module switching, thereby reducing switching vulnerabilities while maintaining application flexibility.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If resource sharing between secure world and normal world is allowed, then system efficiency is improved, but cache leakage risk increases

Engineering Contradiction:
Improvesystem efficiencyVSAvoidcache leakage risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the cache memory into separate secure and non-secure cache regions, physically isolating them to prevent cache leakage. Each cache region is independently managed with its own access control mechanisms, allowing system efficiency through resource sharing while eliminating the cache leakage risk through strict segmentation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces cache isolation gateways as intermediary components that control access between secure and non-secure cache regions. These gateways monitor and regulate cache access operations, preventing unauthorized data exposure while maintaining efficient resource sharing capabilities through controlled intermediation.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If memory access control is strengthened, then security against malicious code is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against malicious codeVSAvoidmemory access control structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions into integrated isolation gateway components that handle memory access control, cache management, and security policy enforcement in a unified architecture. This consolidation reduces the overall device complexity by combining what would otherwise be separate complex subsystems into coordinated single-point-of-control components.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12339954B2Hybrid device with trusted execution environment
Publication Date: 2025.06.24 HONG KONG APPLIED SCI & TECH RES INST
  • US12339954B2 patent drawing
  • US12339954B2 patent drawing
  • US12339954B2 patent drawing

AI summary

A Hybrid TEE device allows a Trusted Execution Environment (TEE) by incorporating hardware comprising a Cache Purging Controller, a Memory Isolation Gateway, and a Memory Clean Up into a System on a Chip device, a general purpose computing device, or a special purpose or proprietary computing or electronic device. The addition of the hardware enables a method of protecting the Trusted Execution Environment and thus reducing vulnerability to malicious software or other program code.