Processor Secure Enclave Isolation for IoT Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional solutions for establishing a trusted execution environment (TEE) in electronic devices, particularly in the Internet of Things and artificial intelligence fields, face challenges in ensuring secure information transmission and efficiency due to complex processor architectures and independent security chips.
Innovation Solution
A processing unit is designed to establish secure enclaves using a Physical Memory Protection mechanism, allowing for secure execution of application programs by creating crypto and runtime enclaves, and ensuring secure boot processes through hash value verification, thereby isolating and protecting sensitive information within the processing unit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a complex processor architecture and independent security chip are used to establish TEE, then security protection function is provided, but transmission efficiency is low and security performance cannot be guaranteed
Solution Approach 1:
The patent merges the security chip functionality directly into the processor by integrating the secure monitor, crypto enclave, and runtime enclave into the processor's memory management unit. This integration eliminates the need for separate security chips and improves transmission efficiency while maintaining security protection through hardware-level encryption and isolation mechanisms.
Solution Approach 2:
The patent segments the memory space into distinct enclaves (crypto enclave, runtime enclave, application enclaves) with isolated address spaces and permission settings. Each enclave operates independently with its own security context, allowing efficient parallel execution while maintaining strong security boundaries through hardware-enforced memory protection.
2Reliability
If a complex processor architecture and independent security chip are used to establish TEE, then security protection function is provided, but device complexity increases
Solution Approach 1:
The patent combines security functions (secure monitor, crypto operations, enclave management) directly into the processor's existing memory management unit rather than requiring separate security chips. This integration reduces device complexity by eliminating external security components while maintaining comprehensive security protection through unified hardware enforcement.
3Reliability
If multiple application enclaves are established for independent protection, then security against information theft is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal enclave management mechanism where the secure monitor provides standardized interfaces for creating, managing, and switching between multiple application enclaves. Each enclave uses the same underlying hardware protection mechanisms and permission models, allowing complex multi-enclave scenarios to be managed through consistent, simplified operations rather than requiring separate management logic for each enclave.
Data Source
AI summary
A processing unit includes a processor that is adapted to start a secure monitor and establish and set one or more of a crypto enclave and a runtime enclave. The processor is further adapted to establish a plurality of application enclaves and set each of the plurality of application enclaves. The processor is furthermore adapted to and check a to-be-started application program to ensure that the application program can be run securely.


