Secure Stashing Decision Circuitry for Trusted Execution Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In data processing systems, there is a need to reduce latency in accessing data while ensuring security, particularly when stashing transactions are redirected to storage structures accessible by processing elements operating in trusted execution environments, as existing methods may compromise security by allowing untrusted processes to access sensitive data.
Innovation Solution
The implementation of secure stashing decision circuitry that receives stashing transactions, checks for a trusted execution environment identifier, and only redirects permitted transactions to storage structures within the same trusted environment, ensuring that data access is secure and performance is improved by reducing latency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of time
If stashing transactions are redirected to storage structures accessible by processing elements, then data access latency is reduced, but security is compromised allowing untrusted processes to access sensitive data
Solution Approach 1:
The patent introduces secure stashing decision circuitry as an intermediary component between devices and storage structures. This circuitry intercepts stashing transactions, verifies trusted execution environment identifiers, and determines whether redirection is permitted. By acting as a mediator, it enables performance optimization through redirection while simultaneously enforcing security policies to prevent untrusted access, thus resolving the contradiction between latency reduction and security maintenance.
2Productivity
If stashing transactions are allowed to access storage structures, then system performance is improved, but data isolation between trusted execution environments is compromised
Solution Approach 1:
The patent implements local quality by making storage access permissions specific to each trusted execution environment context. The secure stashing decision circuitry examines the trusted execution environment identifier in each transaction and applies different access rules accordingly. This allows performance optimization for authorized environments while maintaining strict data isolation for unauthorized ones, resolving the contradiction between system performance and data isolation.
3Reliability
If redirection requirements are strictly enforced based on trusted execution environment identifiers, then security is maintained, but device complexity increases
Solution Approach 1:
The patent extracts the security verification logic into a dedicated secure stashing decision circuitry component, separate from the main processing elements and devices. This extraction allows the complex security checking based on trusted execution environment identifiers to be handled by specialized circuitry, maintaining security requirements while preventing the complexity from propagating throughout the entire system. The extracted component handles verification independently, resolving the contradiction between security maintenance and complexity management.
Data Source
AI summary
An apparatus and method are provided, the apparatus comprising: interconnect circuitry to couple a device to one or more processing elements, each processing element operating in a trusted execution environment; and secure stashing decision circuitry to receive stashing transactions from the device and to redirect permitted stashing transactions to a given storage structure accessible to at least one of the one or more processing elements. The secure stashing decision circuitry is configured, in response to receiving a given stashing transaction, to determine whether the given stashing transaction comprises a trusted execution environment identifier associated with a given trusted execution environment, and to treat the given stashing transaction as a permitted stashing transaction when redirection requirements, dependent on the trusted execution environment identifier, are met.


