PCI Device Trusted Execution Environment Cross-Platform Compatibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware-based trusted execution environments, such as Intel SGX, face limitations including slow hardware development pace, platform-specificity, lack of cross-platform compatibility, and vulnerability to remediation issues, which hinder their widespread adoption and flexibility in secure applications like secure web browsing and digital rights management.

Innovation Solution

A cross-platform trusted execution environment solution is provided through standard Peripheral Component Interconnect (PCI) interfaces, enabling secure memory enclaves that are universally available, allowing for faster development and deployment, and supporting cross-platform compatibility, including virtual machine migration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based TEE solutions like Intel SGX are implemented, then security isolation and code integrity are improved, but platform compatibility and cross-platform support deteriorate

Engineering Contradiction:
Improvesecurity isolationVSAvoidplatform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a software layer (virtual machine, hypervisor, or container) as an intermediary between the secure application and the hardware TEE. This intermediary abstracts the hardware-specific TEE interface and provides a standardized interface that works across different platforms. The secure application communicates with the TEE through this intermediary, which handles platform-specific details, thereby maintaining security isolation while achieving cross-platform compatibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If proprietary hardware TEE features are used, then security performance is improved, but ease of deployment and universal availability deteriorate

Engineering Contradiction:
Improvesecurity performanceVSAvoiddeployment ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal software interface layer that can work with multiple different hardware TEE implementations across various platforms. This multi-functional interface allows the same secure application to deploy on different hardware platforms without modification, as the software layer adapts to the specific hardware TEE available on each platform, thereby improving deployment ease while maintaining security performance.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware-specific TEE implementations are used, then security integrity is improved, but adaptability to different virtualization environments deteriorates

Engineering Contradiction:
Improvesecurity integrityVSAvoidvirtualization environment compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the TEE implementation into distinct layers: a platform-specific hardware TEE layer that provides security integrity, and a platform-independent software intermediary layer that provides virtualization environment compatibility. This segmentation allows each layer to specialize in its function - the hardware layer ensures security integrity while the software layer handles adaptability to different virtualization environments through standardized interfaces.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11513825B2System and method for implementing trusted execution environment on PCI device
Publication Date: 2022.11.29 VMWARE INC
  • US11513825B2 patent drawing
  • US11513825B2 patent drawing
  • US11513825B2 patent drawing

AI summary

System and method for providing trusted execution environments uses a peripheral component interconnect (PCI) device of a computer system to receive and process commands to create and manage a trusted execution environment for a software process running in the computer system. The trusted execution environment created in the PCI device is then used to execute operations for the software process.