Security Broker for TEE Service Integrity Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Consumer devices lack the ability to verify that services are executing in Trusted Execution Environments (TEEs) due to restricted access to low-level hardware information, which is essential for ensuring the integrity and confidentiality of services.
Innovation Solution
Introducing broker devices that acquire and store integrity data, enabling consumer devices to verify the integrity of services running in TEEs by interacting with computing devices and processors, using techniques like remote attestation, and providing this data to consumer devices, thus facilitating trust establishment without requiring service participation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If consumer devices attempt to directly verify TEE integrity by accessing low-level hardware information, then verification accuracy improves, but access restrictions prevent this approach
Solution Approach 1:
The patent introduces broker devices as intermediaries between consumer devices and TEE-protected services. These broker devices acquire integrity data from the service-providing devices and make it available to consumer devices without requiring direct access to low-level hardware information. This resolves the contradiction by enabling verification accuracy through the broker intermediary while respecting access restrictions.
2Reliability
If consumer devices perform verification directly, then trust establishment improves, but computational burden on service-providing devices increases
Solution Approach 1:
The broker device acts as an intermediary that performs the verification work on behalf of consumer devices. It acquires integrity data from service-providing devices and enables verification without requiring consumer devices to directly access or compute against low-level hardware information. This distributes the computational burden appropriately while maintaining trust establishment.
Solution Approach 2:
The broker device performs preliminary acquisition of integrity data before verification requests from consumer devices. By having the integrity data ready and available through the broker, the system avoids repeated computational overhead on service-providing devices for each verification request, thus reducing their computational burden while maintaining reliability.
3Productivity
If integrity data is stored centrally in broker devices, then verification efficiency improves, but system complexity increases
Solution Approach 1:
The broker device serves as a centralized intermediary that stores and manages integrity data. This centralization improves verification efficiency by allowing consumer devices to obtain integrity data from a single, reliable source without needing to directly access service-providing devices. The added complexity is managed by confining it to the broker layer, which is designed specifically to handle these security and data management functions.
Data Source
AI summary
The technology disclosed herein enable consumer devices to verify the integrity of services running in trusted execution environments. An example method may include: establishing, by a computing device, a trusted execution environment for a service, wherein the trusted execution environment comprises an encrypted storage area; loading, by the computing device, data of the service into the trusted execution environment, wherein the data comprises executable data; detecting, by a computing device, a change of the trusted execution environment that is executing the service; generating, by the computing device, integrity data that represents a state of the trusted execution environment after the change; and transferring, by the computing device, the integrity data to another computing device.


