I/O Subsystem Secure Memory Access via DMAT and MOT

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current trust domain systems do not effectively manage secure memory access transactions between I/O devices and trust domains, lacking a mechanism to ensure only trusted I/O devices can access protected memory regions without compromising the integrity of the virtual machine monitor (VMM) and trusted execution environments (TEEs).

Innovation Solution

Implementing a trusted agent within the I/O subsystem that utilizes multi-key total memory encryption (MKTME) and device memory access tables (DMATs) to authenticate and authorize I/O devices, ensuring only trusted devices can access TEE memory by verifying device identities and memory access permissions, and using memory ownership tables (MOTs) to manage memory access securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If I/O devices are allowed to access trust domain-protected memory, then memory access functionality is improved, but security and isolation of the trust domain deteriorates

Engineering Contradiction:
Improvememory access functionalityVSAvoidsecurity and isolation of trust domain
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an I/O subsystem as an intermediary component between I/O devices and trust domain memory. This subsystem includes authentication logic that verifies I/O devices against device memory access tables (DMATs) and enforces access permissions, allowing controlled memory access while maintaining security isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the VMM is included in the trusted code base, then security and isolation of trust domains is improved, but device complexity and system overhead increases

Engineering Contradiction:
Improvesecurity and isolation of trust domainsVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication and authorization functions from the VMM and implements them in hardware within the I/O subsystem. The I/O subsystem independently verifies device identities against DMATs and enforces access permissions, eliminating the need for VMM involvement in trust domain security operations.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If strict memory protection is enforced, then security of trust domains is improved, but memory access flexibility and productivity deteriorates

Engineering Contradiction:
Improvesecurity of trust domainsVSAvoidmemory access flexibility
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic access control where the I/O subsystem evaluates each memory access request against the DMAT to determine permissions. The system allows different levels of access for different devices and memory regions, enabling flexible and controlled memory access while maintaining security.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11625275B2Technologies for controlling memory access transactions received from one or more I/O devices
Publication Date: 2023.04.11 INTEL CORP
  • US11625275B2 patent drawing
  • US11625275B2 patent drawing
  • US11625275B2 patent drawing

AI summary

Technologies for secure I/O include a compute device, which further includes a processor, a memory, a trusted execution environment (TEE), one or more input/output (I/O) devices, and an I/O subsystem. The I/O subsystem includes a device memory access table (DMAT) programmed by the TEE to establish bindings between the TEE and one or more I/O devices that the TEE trusts and a memory ownership table (MOT) programmed by the TEE when a memory page is allocated to the TEE.