Partition Manager for Trusted Coexisting Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems with a single protected core or partition are insufficient in protecting sensitive data from both rogue users and software viruses, especially as they cannot scale beyond eight processor cores, and rely on low-level OS security mechanisms that can be compromised.

Innovation Solution

The system launches multiple trusted, distinct environments in pre-OS space with hardware-enforced isolation, using a partition manager to establish embedded and main partitions, where each partition has isolated resources, and communicates through a trusted Inter-Partition Bridge, allowing for secure execution and storage of code and data, and leveraging TPM for integrity measurements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single protected core or partition is used, then security is provided for sensitive data, but the system cannot scale beyond eight processor cores and remains vulnerable to rogue users and software viruses

Engineering Contradiction:
ImprovesecurityVSAvoidscalability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system divides the computing platform into multiple isolated partitions (first partition, second partition, third partition) each with its own protected core. This segmentation allows the system to scale beyond eight processor cores while maintaining security boundaries between partitions, resolving the contradiction between security and scalability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of security by implementing hardware-enforced isolation at the partition level rather than relying solely on software-based security mechanisms. This dimensional shift from software to hardware enforcement enables both enhanced security and improved scalability across multiple processor cores.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If low-level OS security mechanisms are used, then some security protection is provided, but these mechanisms can be compromised by attackers

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability to compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a partition manager as an intermediary component that operates in a protected environment between the hardware and the operating systems. This intermediary enforces security policies and manages resource allocation across partitions, providing security protection that cannot be compromised by attacks on individual OS instances.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system establishes security boundaries and trust relationships before operating systems are loaded. The partition manager creates isolated environments and configures hardware enforcement mechanisms in advance, preventing attackers from compromising security through runtime attacks on OS security mechanisms.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If multiple partitions are launched with hardware-enforced isolation, then security and scalability are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The partition manager is designed as a universal component that handles security enforcement, resource allocation, and partition management across all partitions. This multi-functional approach consolidates complexity into a single managed entity rather than duplicating security mechanisms in each partition, reducing overall system complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9235707B2Methods and arrangements to launch trusted, coexisting environments
Publication Date: 2016.01.12 INTEL CORP
  • US9235707B2 patent drawing
  • US9235707B2 patent drawing
  • US9235707B2 patent drawing

AI summary

Methods and arrangements to launch trusted, distinct, co-existing environments are disclosed. Embodiments may launch trusted, distinct, co-existing environments in pre-OS space with high assurance. A hardware-enforced isolation scheme may isolate the partitions to facilitate storage and execution of code and data. In many embodiments, the system may launch a partition manager to establish embedded and main partitions. Embedded partitions may not be visible to the main OS and may host critical operations. A main partition may host a general-purpose OS and user applications, and may manage resources that are not assigned to the embedded partitions. Trustworthiness in the launch of the embedded partition is established by comparing integrity metrics for the runtime environment against integrity measurements of a trusted runtime environment for the embedded partition, e.g., by sealing a cryptographic key with the integrity metrics in a trusted platform module. Other embodiments are described and claimed.