Software-Based TEE via Virtualization for Cross-Platform Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Hardware-based Trusted Execution Environments (TEEs) face limitations such as slow hardware development, proprietary platform dependencies, lack of cross-platform compatibility, and vulnerability to vulnerabilities, which hinder secure code and data protection across systems.

Innovation Solution

A software-based TEE solution utilizing virtualization and memory encryption, providing memory enclaves as secure execution environments, deployable across multiple hardware platforms without requiring special hardware TEE features, leveraging existing hardware virtualization and memory encryption features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based TEE solutions are used, then security isolation and code integrity are improved, but platform compatibility and deployment flexibility deteriorate

Engineering Contradiction:
Improvesecurity isolationVSAvoidplatform compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a software-based copy of hardware TEE functionality through virtualization. The secure enclave virtual machine replicates the isolation and protection capabilities of hardware TEE in software, allowing deployment across platforms without requiring specific hardware features. This copying approach maintains security isolation while achieving broad platform compatibility.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The secure enclave virtual machine is designed to provide universal TEE functionality across diverse hardware platforms. By implementing TEE capabilities through software virtualization rather than hardware-specific features, the solution achieves multi-platform support including VMware, Hyper-V, and KVM, making the security functionality universal rather than platform-dependent.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If hardware-based TEE solutions are used, then security protection is improved, but development pace and vulnerability remediation deteriorate

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevelopment pace
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical hardware-based TEE system with a software-based virtualization system. This substitution allows for rapid development, deployment, and updates of security features without requiring hardware manufacturing cycles. Security vulnerabilities can be remediated through software updates rather than requiring new hardware releases, significantly improving development pace and responsiveness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The software-based secure enclave virtual machine provides dynamic adaptability that hardware cannot match. Security features can be dynamically updated, configured, and remediated without physical changes to the system. This dynamic nature enables rapid response to security threats and continuous improvement of protection mechanisms.

Inventive Principle:
Principle #15Dynamics

3Reliability

If hardware-based TEE solutions are used, then secure execution is improved, but cross-platform migration and infrastructure management deteriorate

Engineering Contradiction:
Improvesecure executionVSAvoidcross-platform migration
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure enclave virtual machine can be copied and migrated across different hardware platforms while maintaining secure execution. The virtualized security environment is platform-agnostic, allowing workloads to be moved between VMware, Hyper-V, KVM, and other virtualization infrastructures without losing security guarantees or requiring platform-specific hardware features.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If software-based virtualization is used, then platform compatibility and deployment flexibility are improved, but security isolation and attack surface reduction deteriorate

Engineering Contradiction:
Improveplatform compatibilityVSAvoidsecurity isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a hypervisor as an intermediary layer that provides secure isolation between virtual machines while maintaining platform compatibility. The hypervisor acts as a mediator that enforces security boundaries and controls access to hardware resources, enabling strong security isolation through software while preserving broad platform support and deployment flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11693952B2System and method for providing secure execution environments using virtualization technology
Publication Date: 2023.07.04 VMWARE INC
  • US11693952B2 patent drawing
  • US11693952B2 patent drawing
  • US11693952B2 patent drawing

AI summary

System and method for providing secure execution environments in a computer system uses an enclave virtual computing instance to create a secure execution environment, which is deployed in response to a request for such a secure execution environment for content from a software process running in the computer system.