Peripheral Trusted Execution With Encryption for Untrusted Hosts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Peripheral devices used for processing sensitive code and data face security challenges due to the untrusted nature of the host computing device, which can compromise the confidentiality and integrity of the sensitive information transferred through it.

Innovation Solution

A peripheral device with a security module forms a trusted execution environment (TEE) to process sensitive data, using encryption units to secure data transfers and attest to the trusted computing entity, and implements a mode switch to ensure secure access control and communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is transferred through the host computing device, then communication between trusted computing entities is enabled, but security and confidentiality of sensitive data is compromised due to untrusted host

Engineering Contradiction:
Improvecommunication capabilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces encryption units as intermediary components that mediate data transfer through the untrusted host. These encryption units encrypt data before transmission and decrypt it at the receiving end, ensuring that the host cannot access or compromise the sensitive data during transit. This resolves the contradiction by enabling communication through the host while maintaining security through the intermediary encryption mechanism.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a secure, isolated execution environment (enclave) within the peripheral device that acts as an inert atmosphere for sensitive data processing. This enclave prevents the untrusted host from accessing or interfering with the data, allowing secure computation to occur even though the data must pass through the host system. The enclave provides a protected space that neutralizes the security risks of the untrusted host environment.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

2Productivity

If peripheral device processes sensitive data, then computational efficiency is improved, but security risks increase due to additional attack vectors

Engineering Contradiction:
Improveprocessing efficiencyVSAvoidsecurity threats
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the peripheral device into distinct functional components: compute elements for processing, encryption units for security, and a security module for key management. This segmentation allows the compute elements to efficiently process data while the encryption units and security module provide dedicated security functions, reducing the attack surface by separating security-critical operations from general-purpose computation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts security-critical functions (encryption, decryption, key management) into dedicated hardware components that operate independently from the main compute elements. This extraction ensures that even if the compute elements are compromised, the security functions remain protected and can independently verify and protect data integrity throughout the processing pipeline.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If trusted execution environment is formed, then security of sensitive code is improved, but device complexity increases due to mode switching mechanisms

Engineering Contradiction:
Improvecode securityVSAvoidmode switching mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic mode switching that allows the peripheral device to transition between secure and non-secure operational modes as needed. The security module can dynamically provision encryption keys to encryption units when secure processing is required, and revoke them when not needed. This dynamic approach provides strong security when required while maintaining operational flexibility and reducing complexity compared to permanently dedicated secure hardware.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent designs the encryption units and security module to serve multiple functions: they handle encryption/decryption for data in transit, protect sensitive data in storage, verify data integrity, and manage security credentials. This multi-functionality reduces overall device complexity by using a single security subsystem for multiple security requirements rather than separate dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3850518B1Peripheral device
Publication Date: 2025.07.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP3850518B1 patent drawingFigure 1
  • EP3850518B1 patent drawingFigure 2
  • EP3850518B1 patent drawingFigure 3

AI summary

A peripheral device, for use with a host, comprises one or more compute elements a security module and at least one encryption unit. The security module is configured to form a trusted execution environment on the peripheral device for processing sensitive data using sensitive code. The sensitive data and sensitive code are provided by a trusted computing entity which is in communication with the host computing device. The at least one encryption unit is configured to encrypt and decrypt data transferred between the trusted execution environment and the trusted computing entity via the host computing device. The security module is configured to compute and send an attestation to the trusted computing entity to attest that the sensitive code is in the trusted execution environment.