Secure Zone Manager for Multi-TEE Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for application and storage isolation in secure devices face limitations, including shared hardware vulnerabilities, platform dependency, and difficulty in reconfiguration, particularly with software-based solutions like containers and virtual machines, which expose sensitive data and are restricted to specific interfaces or operating systems.
Innovation Solution
A secure computing system incorporating a memory device with a cryptoprocessor and controller, utilizing a trusted execution environment (TEE) and virtualized TEE (vTEE) systems, along with key management services, to enable secure storage and application isolation through authenticated operations, cryptographic measurements, and secure key management, allowing multiple secure zones on a single processor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software containers are used for application isolation, then applications can be shielded from one another, but shared hardware resources create security vulnerabilities
Solution Approach 1:
The patent divides the secure processing resources into multiple isolated secure zones within the TEE, where each zone can host separate application instances with dedicated cryptographic resources. This segmentation prevents shared hardware vulnerabilities from affecting all applications simultaneously, as each application operates in its own isolated secure environment with dedicated access to cryptographic accelerators and key storage.
Solution Approach 2:
The patent introduces a secure zone manager as an intermediary layer between the external environment and the secure processing zones. This manager handles authentication, authorization, and resource allocation, mediating access to cryptographic resources and preventing direct exposure of shared hardware vulnerabilities to applications.
2Reliability
If virtual machines are used for storage isolation, then data exposure is reduced, but they are platform-dependent and tightly bound to hardware architecture
Solution Approach 1:
The patent creates a platform-independent secure execution environment by implementing secure zones that can host multiple virtual machine instances across different hardware architectures. The TEE provides universal cryptographic primitives and secure storage abstractions that work consistently across diverse platforms, allowing the same secure application to be deployed on different hardware without reconfiguration.
3Reliability
If dedicated TEE is used for secure processing, then security from software vulnerabilities is provided, but it occupies a single trusted zone and is difficult to reconfigure
Solution Approach 1:
The patent transforms the static single-zone TEE architecture into a dynamic multi-zone system where secure zones can be created, modified, and destroyed on-demand. The secure zone manager dynamically allocates cryptographic resources and adjusts zone configurations based on application requirements, enabling hot reconfiguration without requiring physical hardware changes or system reboots.
Solution Approach 2:
The patent extends the traditional single-dimensional TEE architecture by adding a temporal dimension to secure zone management. Secure zones can be activated and deactivated at different times, and their resource allocations can change dynamically, allowing the system to adapt to varying security requirements throughout the system's operational lifecycle.
4Reliability
If vTEE systems are used to run multiple TEEs on a single processor, then improved security is achieved, but they remain software-based and subject to the same vulnerabilities as containers and virtual machines
Solution Approach 1:
The patent merges the benefits of hardware-based security with the flexibility of virtualization by implementing secure zones that are enforced by hardware boundaries but managed through software. The TEE hardware provides immutable security boundaries and dedicated cryptographic resources, while the secure zone manager software enables dynamic creation and management of multiple isolated secure environments, combining hardware reliability with software adaptability.
Data Source
AI summary
Disclosed are methods, devices, and computer-readable media for securing data in motion and at rest in a secure memory device. In one embodiment, a memory device is disclosed comprising a storage medium and a processor, the processor configured to: receive a software image, validate a digital signature associated with the software image, write the software image to the storage medium, receive a request to launch the software image from a host processor, validate the software image, and transmit the software image to the host processor.


