I/O Subsystem Secure Memory Access via DMAT and MOT
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current trust domain systems do not effectively manage secure memory access transactions between I/O devices and trust domains, lacking a mechanism to ensure only trusted I/O devices can access protected memory regions without compromising the integrity of the virtual machine monitor (VMM) and trusted execution environments (TEEs).
Innovation Solution
Implementing a trusted agent within the I/O subsystem that utilizes multi-key total memory encryption (MKTME) and device memory access tables (DMATs) to authenticate and authorize I/O devices, ensuring only trusted devices can access TEE memory by verifying device identities and memory access permissions, and using memory ownership tables (MOTs) to manage memory access securely.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If I/O devices are allowed to access trust domain-protected memory, then memory access functionality is improved, but security and isolation of the trust domain deteriorates
Solution Approach 1:
The patent introduces an I/O subsystem as an intermediary component between I/O devices and trust domain memory. This subsystem includes authentication logic that verifies I/O devices against device memory access tables (DMATs) and enforces access permissions, allowing controlled memory access while maintaining security isolation.
2Reliability
If the VMM is included in the trusted code base, then security and isolation of trust domains is improved, but device complexity and system overhead increases
Solution Approach 1:
The patent extracts the authentication and authorization functions from the VMM and implements them in hardware within the I/O subsystem. The I/O subsystem independently verifies device identities against DMATs and enforces access permissions, eliminating the need for VMM involvement in trust domain security operations.
3Reliability
If strict memory protection is enforced, then security of trust domains is improved, but memory access flexibility and productivity deteriorates
Solution Approach 1:
The patent implements dynamic access control where the I/O subsystem evaluates each memory access request against the DMAT to determine permissions. The system allows different levels of access for different devices and memory regions, enabling flexible and controlled memory access while maintaining security.
Data Source
AI summary
Technologies for secure I/O include a compute device, which further includes a processor, a memory, a trusted execution environment (TEE), one or more input/output (I/O) devices, and an I/O subsystem. The I/O subsystem includes a device memory access table (DMAT) programmed by the TEE to establish bindings between the TEE and one or more I/O devices that the TEE trusts and a memory ownership table (MOT) programmed by the TEE when a memory page is allocated to the TEE.


