Secure Execution Environment Interface for Distributed Memory Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems (IHS) face security threats from malware, with existing secure execution environments (SEEs) not providing a secure solution across diverse platforms, leading to unauthorized access and data compromise.

Innovation Solution

A method and system for security management across diverse execution environments, involving a secure execution environment interface associated with each execution environment, prompting for and verifying security credentials to access secure memory regions, and executing subroutines within these regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If diverse execution environments are supported, then adaptability is improved, but security consistency deteriorates

Engineering Contradiction:
Improvesupport for diverse execution environmentsVSAvoidsecurity consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a service processor as an intermediary component that mediates between diverse execution environments and the secure memory region. This service processor provides a unified security management interface that translates and coordinates access requests across different execution environments (EOH, EOC, SEEaaS), ensuring consistent security policies are applied while maintaining adaptability to various platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure execution environments are implemented, then data protection is improved, but system complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The service processor is designed as a universal security management component that handles multiple execution environment types (EOH, EOC, SEEaaS) through a single interface. This multi-functional approach consolidates security management responsibilities, reducing overall system complexity while maintaining strong data protection across diverse execution environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If access control is enforced, then unauthorized access is prevented, but operational ease deteriorates

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidaccess operation ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The service processor implements self-service security management by automatically handling authentication, credential verification, and access control decisions. The system autonomously manages security policies and access rights without requiring manual intervention, thereby maintaining strong access control while simplifying operational procedures for legitimate users.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10938857B2Management of a distributed universally secure execution environment
Publication Date: 2021.03.02 DELL PROD LP
  • US10938857B2 patent drawing
  • US10938857B2 patent drawing
  • US10938857B2 patent drawing

AI summary

A method and an information handling system for security management across a plurality of diverse execution environments. The method includes associating, based on a distributed computing framework, a secure execution environment interface with each diverse execution environment. The method includes receiving a general access policy to access at least one secure memory region associated with a respective one of the diverse execution environments. In response to a request to access a memory region associated with at least one diverse execution environment, the method includes prompting for entry of security credentials. In response to receiving and verifying the security credentials, the method establishes access to the secure memory region of the respective diverse execution environment. The method includes executing a subroutine to modify at least a subset of the secure memory region, and the method includes returning a result to a distributed application via the secure execution environment interface.