Hyper-Threading Trusted Execution Environment Entry Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In hyper-threading scenarios, the sharing of computing resources such as level 1 caches between logical processors can lead to security risks and privacy leakage, as untrusted applications can access residual privacy data, compromising data confidentiality and integrity.

Innovation Solution

A method and apparatus for securely entering a trusted execution environment (TEE) in a hyper-threading scenario, where a virtual machine monitor labels logical processors with a state of expecting to enter a TEE and controls each processor to enter a TEE built on a physical processor core, using a hypervisor to manage resource access and prevent unauthorized entry.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If hyper-threading technology is used to improve processing efficiency, then productivity increases, but security risks worsen due to resource sharing between logical processors

Engineering Contradiction:
Improveprocessing efficiencyVSAvoiddata confidentiality
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system segments logical processors into different security domains by implementing separate entry procedures for TEE and non-TEE modes. Each logical processor is independently controlled and labeled according to its security state, allowing hyper-threading to maintain productivity while preventing unauthorized cross-contamination of security contexts through resource sharing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The virtual machine monitor acts as an intermediary that mediates between logical processors and the TEE entry mechanism. It labels logical processors with security states and controls the transition to TEE mode, ensuring that resource sharing in hyper-threading does not compromise security by preventing untrusted applications from accessing TEE resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If logical processors share computing resources like level 1 caches, then device complexity is reduced, but harmful factors increase due to potential privacy data access by untrusted applications

Engineering Contradiction:
Improveresource sharing structureVSAvoidprivacy leakage risk
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The system performs preliminary labeling of logical processors with security states before they access shared resources. The virtual machine monitor pre-establishes the security context for each logical processor, ensuring that even when sharing resources like level 1 caches, untrusted applications cannot inadvertently or maliciously access privacy data from trusted applications.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If all logical processors enter TEE simultaneously, then security is improved, but loss of time increases due to synchronization requirements

Engineering Contradiction:
Improvesecurity assuranceVSAvoidsynchronization delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements dynamic control of TEE entry for logical processors. Rather than forcing simultaneous entry, the virtual machine monitor allows logical processors to enter TEE mode dynamically as needed, with each processor's entry independently controlled based on its labeling state and security requirements, reducing unnecessary synchronization delays while maintaining security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3961446B1Method and apparatus for securely entering trusted execution environment in hyper-threading scenario
Publication Date: 2023.04.19 ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
  • EP3961446B1 patent drawingFigure 1~2
  • EP3961446B1 patent drawingFigure 3~4
  • EP3961446B1 patent drawingFigure 5~6

AI summary

One or more implementations of the present specification provide a method and apparatus for securely entering a trusted execution environment in a hyper-threading scenario. The method can include: in response to that a logical processor running on a physical processor core generates a trusted execution environment entry event through an approach provided by a virtual machine monitor, labeling the logical processor with a state of expecting to enter a trusted execution environment; and in response to determining that all logical processors corresponding to the physical processor core are labeled with the state of expecting to enter a trusted execution environment, separately controlling each one of the logical processors to enter a trusted execution environment built on the physical processor core. In either a privacy blockchain scenario or other privacy protection scenarios, the solution above can allow the hyper-threading technology to be enabled to improve computing efficiency while ensuring that a trusted application exclusively occupies a physical processor core to avoid a risk of privacy leakage.