Security Broker for TEE Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Consumer devices lack the ability to verify that services are executing in Trusted Execution Environments (TEEs) due to restricted access to low-level hardware information, which is essential for ensuring the integrity and confidentiality of services.

Innovation Solution

A broker device is introduced to acquire and store integrity data, enabling consumer devices to verify the execution of services in TEEs by interacting with the computing device's processors and providing this data to consumers, thereby facilitating trust verification without requiring service participation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If consumer devices access low-level hardware information to verify TEE integrity, then verification capability is improved, but access restrictions and security policies prevent this access

Engineering Contradiction:
Improveverification capabilityVSAvoidaccess restriction
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a broker device as an intermediary between consumer devices and service-providing devices. The broker acquires integrity data from the service-providing device's processor and provides it to consumer devices, enabling verification without requiring consumer devices to directly access restricted hardware information. This mediator resolves the contradiction by facilitating verification capability while respecting access restrictions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If consumer devices perform verification directly, then verification accuracy is improved, but computational burden on service-providing devices increases

Engineering Contradiction:
Improveverification accuracyVSAvoidcomputational burden
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The verification process is segmented into distinct functional components: the service-providing device's processor generates integrity data, the broker device acquires and manages this data, and consumer devices perform verification using the provided data. This segmentation allows verification accuracy to be maintained while distributing computational responsibilities, reducing the burden on service-providing devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The broker device acts as a mediator that handles the acquisition and distribution of integrity data, eliminating the need for consumer devices to directly interact with service-providing devices for data collection. This reduces computational burden on service-providing devices while maintaining verification accuracy through reliable data provision.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If integrity data is provided to multiple consumer devices, then verification availability is improved, but data management complexity increases

Engineering Contradiction:
Improveverification availabilityVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The broker device is designed as a universal platform that serves multiple consumer devices simultaneously. It maintains a repository of integrity data that can be provided to any consumer device requesting verification, improving verification availability across the system. The broker handles data management centrally, reducing complexity for individual devices while supporting multiple consumers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11856002B2Security broker with consumer proxying for tee-protected services
Publication Date: 2023.12.26 RED HAT LLC
  • US11856002B2 patent drawing
  • US11856002B2 patent drawing
  • US11856002B2 patent drawing

AI summary

The technology disclosed herein enable a consumer to verify the integrity of services running in trusted execution environments. An example method may include: receiving, by a broker device, a request to verify that a service is executing in a trusted execution environment, wherein the request comprises data identifying the service; determining, by the broker device, a computing device that is executing the service; initiating, by the broker device, a remote integrity check of the computing device executing the service; receiving, by the broker device, integrity data of the trusted execution environment of the computing device; and providing, by the broker device, the integrity data to a consumer device associated with the service.