Secure Stashing Decision Circuitry for Trusted Execution Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In data processing systems, there is a need to reduce latency in accessing data while ensuring security, particularly when stashing transactions are redirected to storage structures accessible by processing elements operating in trusted execution environments, as existing methods may compromise security by allowing untrusted processes to access sensitive data.

Innovation Solution

The implementation of secure stashing decision circuitry that receives stashing transactions, checks for a trusted execution environment identifier, and only redirects permitted transactions to storage structures within the same trusted environment, ensuring that data access is secure and performance is improved by reducing latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If stashing transactions are redirected to storage structures accessible by processing elements, then data access latency is reduced, but security is compromised allowing untrusted processes to access sensitive data

Engineering Contradiction:
Improvedata access latencyVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent introduces secure stashing decision circuitry as an intermediary component between devices and storage structures. This circuitry intercepts stashing transactions, verifies trusted execution environment identifiers, and determines whether redirection is permitted. By acting as a mediator, it enables performance optimization through redirection while simultaneously enforcing security policies to prevent untrusted access, thus resolving the contradiction between latency reduction and security maintenance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If stashing transactions are allowed to access storage structures, then system performance is improved, but data isolation between trusted execution environments is compromised

Engineering Contradiction:
Improvesystem performanceVSAvoiddata isolation violation
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements local quality by making storage access permissions specific to each trusted execution environment context. The secure stashing decision circuitry examines the trusted execution environment identifier in each transaction and applies different access rules accordingly. This allows performance optimization for authorized environments while maintaining strict data isolation for unauthorized ones, resolving the contradiction between system performance and data isolation.

Inventive Principle:
Principle #3Local quality

3Reliability

If redirection requirements are strictly enforced based on trusted execution environment identifiers, then security is maintained, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcircuitry complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security verification logic into a dedicated secure stashing decision circuitry component, separate from the main processing elements and devices. This extraction allows the complex security checking based on trusted execution environment identifiers to be handled by specialized circuitry, maintaining security requirements while preventing the complexity from propagating throughout the entire system. The extracted component handles verification independently, resolving the contradiction between security maintenance and complexity management.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240193260A1Apparatus and method for handling stashing transactions
Publication Date: 2024.06.13 ARM LTD
  • US20240193260A1 patent drawing
  • US20240193260A1 patent drawing
  • US20240193260A1 patent drawing

AI summary

An apparatus and method are provided, the apparatus comprising: interconnect circuitry to couple a device to one or more processing elements, each processing element operating in a trusted execution environment; and secure stashing decision circuitry to receive stashing transactions from the device and to redirect permitted stashing transactions to a given storage structure accessible to at least one of the one or more processing elements. The secure stashing decision circuitry is configured, in response to receiving a given stashing transaction, to determine whether the given stashing transaction comprises a trusted execution environment identifier associated with a given trusted execution environment, and to treat the given stashing transaction as a permitted stashing transaction when redirection requirements, dependent on the trusted execution environment identifier, are met.