Processor Secure Enclave Isolation for IoT Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional solutions for establishing a trusted execution environment (TEE) in electronic devices, particularly in the Internet of Things and artificial intelligence fields, face challenges in ensuring secure information transmission and efficiency due to complex processor architectures and independent security chips.

Innovation Solution

A processing unit is designed to establish secure enclaves using a Physical Memory Protection mechanism, allowing for secure execution of application programs by creating crypto and runtime enclaves, and ensuring secure boot processes through hash value verification, thereby isolating and protecting sensitive information within the processing unit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a complex processor architecture and independent security chip are used to establish TEE, then security protection function is provided, but transmission efficiency is low and security performance cannot be guaranteed

Engineering Contradiction:
Improvesecurity protectionVSAvoidtransmission efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the security chip functionality directly into the processor by integrating the secure monitor, crypto enclave, and runtime enclave into the processor's memory management unit. This integration eliminates the need for separate security chips and improves transmission efficiency while maintaining security protection through hardware-level encryption and isolation mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the memory space into distinct enclaves (crypto enclave, runtime enclave, application enclaves) with isolated address spaces and permission settings. Each enclave operates independently with its own security context, allowing efficient parallel execution while maintaining strong security boundaries through hardware-enforced memory protection.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a complex processor architecture and independent security chip are used to establish TEE, then security protection function is provided, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessor architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines security functions (secure monitor, crypto operations, enclave management) directly into the processor's existing memory management unit rather than requiring separate security chips. This integration reduces device complexity by eliminating external security components while maintaining comprehensive security protection through unified hardware enforcement.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple application enclaves are established for independent protection, then security against information theft is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against information theftVSAvoidenclave management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal enclave management mechanism where the secure monitor provides standardized interfaces for creating, managing, and switching between multiple application enclaves. Each enclave uses the same underlying hardware protection mechanisms and permission models, allowing complex multi-enclave scenarios to be managed through consistent, simplified operations rather than requiring separate management logic for each enclave.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240273241A1Processing unit, electronic device, and security control method
Publication Date: 2024.08.15 ALIBABA GROUP HOLDING LTD
  • US20240273241A1 patent drawing
  • US20240273241A1 patent drawing
  • US20240273241A1 patent drawing

AI summary

A processing unit includes a processor that is adapted to start a secure monitor and establish and set one or more of a crypto enclave and a runtime enclave. The processor is further adapted to establish a plurality of application enclaves and set each of the plurality of application enclaves. The processor is furthermore adapted to and check a to-be-started application program to ensure that the application program can be run securely.