Secure Enclave Fast Boot via Dynamic Root of Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Industrial Internet-of-things (IIoT) devices, particularly in automotive environments, face challenges in meeting fast-boot performance requirements due to the time-consuming nature of protected boot methods, which hinder the rapid establishment of a trusted execution environment and compromise boot-time KPIs.
Innovation Solution
The implementation of a dynamic root-of-trust measurement process that allows for quick entry into a trusted environment by bypassing traditional protected boot operations, using a secure enclave and hardware-backed measurements to verify both trusted and untrusted applications without relying on sequential boot methods, enabling fast and secure boot operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If protected boot methods are used to establish a trusted execution environment, then security and reliability are improved, but boot time increases beyond acceptable KPIs
Solution Approach 1:
The system segments the boot process into two distinct paths: a fast boot path that bypasses traditional protected boot for immediate execution, and a secure verification path that uses dynamic root-of-trust measurements to verify untrusted applications at runtime. This segmentation allows the trusted execution environment to be established quickly while security verification occurs asynchronously or on-demand.
Solution Approach 2:
The system performs preliminary setup of the trusted execution environment through secure enclave initialization before full protected boot completion. The secure enclave is pre-configured with root-of-trust hardware, allowing it to immediately provide trusted services without waiting for the complete protected boot sequence to finish.
2Reliability
If traditional protected boot methods are implemented, then trust verification is improved, but boot performance fails to meet KPIs
Solution Approach 1:
The system replaces the mechanical sequential protected boot process with a hybrid approach that uses virtualized secure enclaves and dynamic measurement verification. Instead of linearly verifying each boot component in sequence, the system uses virtual machine-based isolation with runtime integrity checks, substituting the traditional boot verification mechanism with a more efficient virtualized trust model.
Solution Approach 2:
The secure enclave acts as an intermediary between the untrusted execution environment and the trusted root-of-trust hardware. It mediates trust verification by providing attestation services that confirm the integrity of untrusted applications without requiring the entire boot process to be protected, thus decoupling trust verification from the boot performance path.
3Loss of time
If secure enclaves with dynamic measurements are used, then fast boot KPIs are met, but traditional protected boot security is reduced
Solution Approach 1:
The system changes the verification parameter from static pre-boot integrity checks to dynamic runtime measurements. Instead of verifying application integrity before execution through protected boot, the system performs integrity measurements dynamically while the application is running within the secure enclave, using hardware-based measurement registers that capture runtime state rather than pre-execution state.
Solution Approach 2:
The system transitions from static protected boot verification to dynamic trust verification. The secure enclave continuously performs root-of-trust measurements of untrusted applications during runtime, allowing the trust verification process to adapt to changing system states rather than being fixed at boot time. This dynamic approach maintains security while enabling fast boot.
Data Source
AI summary
Methods, apparatus, systems and machine-readable storage media to enable fast boot of secure and unsecure environments in a computing system are disclosed. Root of trust hardware is used to provide dynamic root of trust measurements of various virtual machines, operating systems, and application environments within the computing system. In an example, a trusted application for a trusted environment is initiated with a fast boot process, with use of a secure enclave accessed by an operating system and virtual machine. The root of trust hardware is used to perform dynamic integrity measurements of a second virtual machine and an untrusted application, to later initiate this untrusted application securely after verification of the integrity measurements. Further uses and coordination of dynamic root of trust measurements and application execution, booting, and security verification processes are also described.


