Secure Enclave SiP Using FPGA Isolation for Trusted Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems rely on general-purpose CPUs, which are complex, opaque, and often compromised, leading to a lack of trust and privacy for data and software in remote server environments, as they require trust in manufacturers with potential hardware and software backdoors.

Innovation Solution

A secure enclave system-in-package (SE-SiP) using system-in-package technology, incorporating a configurable logic device (CLD) or field programmable gate array (FPGA) as a trustworthy processing element, providing hardware-based security functions and eliminating the need to trust the CPU manufacturer, with physical and electrical protection through a Privacy and Integrity Mechanism (PIM).

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a general-purpose CPU is used in a remote server system, then computing functionality and versatility are improved, but system trustworthiness and data privacy deteriorate due to manufacturer backdoors and lack of physical security

Engineering Contradiction:
Improvecomputing functionalityVSAvoidsystem trustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into separate functional components: a secure enclave containing a trusted processor and TPM, and a separate general-purpose CPU. The secure enclave handles security-critical operations while the general-purpose CPU provides computing versatility. This segmentation allows the system to maintain both adaptability and trustworthiness by isolating security functions from the potentially compromised general-purpose processing.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure enclave acts as an intermediary between the untrusted external environment (including the general-purpose CPU and network) and the sensitive data/operations. The enclave's trusted processor and TPM verify and protect data exchanges, mediating all security-sensitive operations while allowing the general-purpose CPU to maintain its computing functionality without direct access to protected resources.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a TPM-based security system is implemented, then hardware-based security functions are improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improvehardware-based securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the TPM and trusted processor into a single integrated secure enclave package. This merging reduces the number of separate components and interconnections needed, simplifying the overall system architecture while maintaining all the security functions of both the TPM and trusted processor. The integrated design reduces manufacturing complexity compared to implementing separate TPM and trusted processing components.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If multiple I/O ports and communication interfaces are provided for system functionality, then adaptability and ease of operation are improved, but security and privacy protection deteriorate due to increased attack surfaces

Engineering Contradiction:
Improvesystem accessibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Different I/O interfaces and communication channels are assigned different security characteristics. Critical security-sensitive interfaces are protected through the secure enclave's trusted processor and TPM verification, while less sensitive interfaces have reduced protection. This local differentiation of security quality allows the system to maintain ease of operation with multiple interfaces while concentrating security protections where most needed.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12536119B2Secure enclave system-in-package
Publication Date: 2026.01.27 OCTAVO SYSTEMS LLC
  • US12536119B2 patent drawing
  • US12536119B2 patent drawing
  • US12536119B2 patent drawing

AI summary

A Secure Enclave SiP (SE-SiP) is disclosed, which is an improvement to Trusted Platform Module (TPM) concepts, and in certain aspects, is a general-purpose next-generation security building block that provides all the security benefits of a system designed using a TPM, replaces the need to trust a general-purpose CPU chip vendor with the need to trust a much simpler more trustworthy configurable device, and replaces the need to trust the entire system motherboard manufacturer with the much more limited need to trust the SE-SiP manufacturer. It can provide privacy for the software and data sent to the system, resident on it, or retrieved from it, with respect to all parties—including the person/party in physical possession of the device.