PCIe Protection Controller for Secure Endpoint Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for securing PCIe endpoint devices are inadequate, as they either require new device support, incur performance costs, or fail to protect against malicious REE supervisor or hypervisor attacks, and are inflexible in system resource utilization.

Innovation Solution

Implementing a PCIe protection controller that dynamically partitions PCIe endpoint devices into secure and nonsecure groups, allowing secure devices write access to secure memory and protecting against access from nonsecure components, with control from a trusted execution environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If PCIe device security enhancements are implemented through firmware measurement and device authentication, then device security is improved, but the solution only applies to future devices and cannot protect existing PCIe endpoint devices

Engineering Contradiction:
Improvedevice securityVSAvoidcompatibility with existing devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a PCIe protection controller as an intermediary component between the REE and secure endpoint devices. This controller enforces security policies and filters access requests, allowing protection of existing devices without requiring firmware changes or device authentication mechanisms. The protection controller acts as a mediator that can protect both legacy and modern devices uniformly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption features are added to PCIe extensions, then data confidentiality is improved, but performance costs increase in highly performance-sensitive applications

Engineering Contradiction:
Improvedata confidentialityVSAvoidapplication performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the encryption function from the access control mechanism and delegates it to the trusted execution environment. The protection controller enforces access policies without performing encryption/decryption operations itself, allowing confidential data to be processed in plaintext within the TEE while maintaining security through controlled access rather than cryptographic overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If security settings are defined statically at design time, then protection against REE attacks is improved, but system resource utilization becomes inflexible

Engineering Contradiction:
Improveprotection against REE attacksVSAvoidsystem resource utilization flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security configuration where the protection controller can modify security policies and device group assignments at runtime based on TEE software control. Security settings are not fixed at design time but can be adjusted dynamically to match changing system requirements, enabling both strong protection and flexible resource utilization.

Inventive Principle:
Principle #15Dynamics

4Reliability

If all PCIe devices are isolated from REE, then security protection is improved, but system resource utilization becomes inflexible

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem resource utilization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments PCIe endpoint devices into different security groups (secure and nonsecure) rather than applying uniform isolation. The protection controller selectively enforces security policies based on device group membership and request origin, allowing some devices to be protected from REE while others remain accessible, thereby balancing security protection with system resource utilization flexibility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12079379B2Peripheral component interconnect express protection controller
Publication Date: 2024.09.03 HUAWEI TECH CO LTD
  • US12079379B2 patent drawing
  • US12079379B2 patent drawing
  • US12079379B2 patent drawing

AI summary

The disclosed systems, structures, and methods are directed to a computer system including a PCIe protection controller as a part of a PCIe root complex that includes at least one root port. Each root port is configured to optionally connect to at least one endpoint device, and each endpoint device is designated as a secure endpoint device or a nonsecure endpoint device. The PCIe protection controller is configured to control outbound traffic to protect secure endpoint devices from access from any nonsecure components of the computer system. The PCIe protection controller may be further configured to control inbound traffic to prevent access to secure memory by nonsecure endpoint devices. The PCIe protection controller may be dynamically configured at runtime to designate endpoint devices as either secure or nonsecure.