Secure Processing Hardware Module for Application Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securely executing multiple applications on a shared processing unit fail to provide adequate isolation and protection, as they rely on software-based operating systems that can be exploited or are costly and limited in scalability, especially when dealing with mutually-distrusting applications.

Innovation Solution

A hardware module, such as a Secure-Processing (SEP) hardware module, is configured to execute applications on a shared processing unit while ensuring isolation through application-specific keys and memory encryption, preventing access to other applications' data, even when running on the same processor, without relying on the trustworthiness of software modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based operating systems are used to separate applications, then multiple applications can be executed on a shared processor, but security reliability deteriorates because the OS can be exploited

Engineering Contradiction:
Improveability to execute multiple applicationsVSAvoidsecurity trustworthiness
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces the software-based operating system (mechanical/software system) with a hardware-based security module that provides application separation. The security module is implemented in hardware, creating a trusted execution environment that cannot be exploited like software. This substitution maintains the ability to execute multiple applications while fundamentally improving security reliability by moving the separation mechanism from software to hardware level.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If multiple processors are deployed to ensure application isolation, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improveapplication isolation securityVSAvoidnumber of processors
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple application execution environments into a single processor by introducing a hardware-based security module that creates virtualized secure execution contexts. Instead of requiring separate physical processors for each application, the security module enables multiple applications to run isolated from each other on the same processor. This combining approach maintains strong security isolation while reducing device complexity and cost.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security module serves multiple functions: it provides application separation, enables secure execution of mutually-distrusting applications, manages cryptographic keys, and protects memory contents. This multi-functional hardware component allows a single processor to securely host multiple applications with different security requirements, eliminating the need for separate processors for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If complete separation between applications is implemented, then security is improved, but adaptability deteriorates because applications cannot share data

Engineering Contradiction:
Improveapplication separationVSAvoiddata sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security module acts as an intermediary that mediates data sharing between separated applications. Applications remain isolated in their own secure execution contexts, but the security module provides controlled mechanisms for authorized data exchange. This intermediary approach maintains strict security separation while enabling adaptability for data sharing when needed, resolving the contradiction between isolation and collaboration.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8369526B2Device, system, and method of securely executing applications
Publication Date: 2013.02.05 ARM LTD
  • US8369526B2 patent drawing
  • US8369526B2 patent drawing
  • US8369526B2 patent drawing

AI summary

Device, system, and method of executing secure-processing (SEP) applications. Some demonstrative embodiments include a secure-processing (SEP) hardware module including a processor capable of executing at least one SEP application, wherein the SEP hardware module is configured to perform at least one of encrypting and decrypting data handled by the SEP application using an application-specific application-key corresponding to the SEP application, only if the processor begins execution of the SEP application at an approved entry point of the SEP application, and wherein the application-key corresponding to the SEP application is based at least on an internal key internally stored by the SEP hardware module and on application-specific information corresponding to the SEP application. Other embodiments are described and claimed.