Secure Zone Manager for Multi-TEE Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for application and storage isolation in secure devices face limitations, including shared hardware vulnerabilities, platform dependency, and difficulty in reconfiguration, particularly with software-based solutions like containers and virtual machines, which expose sensitive data and are restricted to specific interfaces or operating systems.

Innovation Solution

A secure computing system incorporating a memory device with a cryptoprocessor and controller, utilizing a trusted execution environment (TEE) and virtualized TEE (vTEE) systems, along with key management services, to enable secure storage and application isolation through authenticated operations, cryptographic measurements, and secure key management, allowing multiple secure zones on a single processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software containers are used for application isolation, then applications can be shielded from one another, but shared hardware resources create security vulnerabilities

Engineering Contradiction:
Improveapplication isolation securityVSAvoidshared hardware vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the secure processing resources into multiple isolated secure zones within the TEE, where each zone can host separate application instances with dedicated cryptographic resources. This segmentation prevents shared hardware vulnerabilities from affecting all applications simultaneously, as each application operates in its own isolated secure environment with dedicated access to cryptographic accelerators and key storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure zone manager as an intermediary layer between the external environment and the secure processing zones. This manager handles authentication, authorization, and resource allocation, mediating access to cryptographic resources and preventing direct exposure of shared hardware vulnerabilities to applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtual machines are used for storage isolation, then data exposure is reduced, but they are platform-dependent and tightly bound to hardware architecture

Engineering Contradiction:
Improvedata protectionVSAvoidplatform independence
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a platform-independent secure execution environment by implementing secure zones that can host multiple virtual machine instances across different hardware architectures. The TEE provides universal cryptographic primitives and secure storage abstractions that work consistently across diverse platforms, allowing the same secure application to be deployed on different hardware without reconfiguration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If dedicated TEE is used for secure processing, then security from software vulnerabilities is provided, but it occupies a single trusted zone and is difficult to reconfigure

Engineering Contradiction:
Improvesecurity isolationVSAvoidreconfiguration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transforms the static single-zone TEE architecture into a dynamic multi-zone system where secure zones can be created, modified, and destroyed on-demand. The secure zone manager dynamically allocates cryptographic resources and adjusts zone configurations based on application requirements, enabling hot reconfiguration without requiring physical hardware changes or system reboots.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent extends the traditional single-dimensional TEE architecture by adding a temporal dimension to secure zone management. Secure zones can be activated and deactivated at different times, and their resource allocations can change dynamically, allowing the system to adapt to varying security requirements throughout the system's operational lifecycle.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If vTEE systems are used to run multiple TEEs on a single processor, then improved security is achieved, but they remain software-based and subject to the same vulnerabilities as containers and virtual machines

Engineering Contradiction:
Improvemulti-TEE securityVSAvoidsoftware-based vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent merges the benefits of hardware-based security with the flexibility of virtualization by implementing secure zones that are enforced by hardware boundaries but managed through software. The TEE hardware provides immutable security boundaries and dedicated cryptographic resources, while the secure zone manager software enables dynamic creation and management of multiple isolated secure environments, combining hardware reliability with software adaptability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11811948B2Flexible security enclave for protecting data at rest and in motion
Publication Date: 2023.11.07 MICRON TECHNOLOGY INC
  • US11811948B2 patent drawing
  • US11811948B2 patent drawing
  • US11811948B2 patent drawing

AI summary

Disclosed are methods, devices, and computer-readable media for securing data in motion and at rest in a secure memory device. In one embodiment, a memory device is disclosed comprising a storage medium and a processor, the processor configured to: receive a software image, validate a digital signature associated with the software image, write the software image to the storage medium, receive a request to launch the software image from a host processor, validate the software image, and transmit the software image to the host processor.