Storage Access Controller for Secure Inter-Enclave Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The efficiency of data transmission between different trusted execution environments (TEEs) in electronic devices is limited, affecting the performance and response speed of devices that require secure and efficient data exchange, such as those involving sensitive information like identity and property information.

Innovation Solution

A processing apparatus with isolated enclaves, including a source enclave, a target enclave, and a runtime enclave, utilizes a storage access controller to establish a secure channel for data transmission between enclaves without requiring processor involvement, ensuring data security and efficiency by configuring channels and managing data transmission based on allocation requests and control rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If data transmission between TEEs is performed through the processor, then data security is maintained, but transmission efficiency and response speed are limited

Engineering Contradiction:
Improvedata transmission efficiencyVSAvoidresponse speed
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent introduces a storage access controller as an intermediary component between the processor and memory enclaves. This controller establishes direct data transmission channels between source and target enclaves, bypassing the processor for actual data movement while maintaining security through controlled access. The processor retains security management functions while the storage access controller handles high-speed data transfer, resolving the contradiction between security and transmission efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the processor is involved in data transmission between enclaves, then security control is maintained, but power consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the data transmission function from the processor and relocates it to a dedicated storage access controller. The processor is removed from the data transmission path, retaining only security management and control functions. This separation allows power-intensive data transfer operations to be handled by specialized hardware with lower power consumption, while the processor consumes less energy by focusing on security control tasks.

Inventive Principle:
Principle #2Taking out (Extraction)

3Speed

If direct data transmission channels are established between enclaves, then transmission speed increases, but system complexity increases

Engineering Contradiction:
Improvedata transmission speedVSAvoidsystem complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The storage access controller is designed as a multi-functional component that handles multiple enclaves and various data transmission operations through a unified interface and control mechanism. Rather than creating separate dedicated channels for each enclave pair, the controller provides universal access capabilities, managing channel establishment, data transmission, and security control through standardized procedures, thereby reducing system complexity while maintaining high transmission speeds.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11899781B2Processing apparatus, embedded system, system-on-chip, and a security control method for inter-enclave data transmission
Publication Date: 2024.02.13 ALIBABA GROUP HOLDING LTD
  • US11899781B2 patent drawing
  • US11899781B2 patent drawing
  • US11899781B2 patent drawing

AI summary

A processing apparatus, an embedded system, a system-on-chip, and a security control method are disclosed. The processing apparatus includes a processor, adapted to execute a program; and a memory, coupled to the processor and adapted to provide a plurality of enclaves isolated from each other. One of the plurality of enclaves is a source enclave, another one of the plurality of enclaves is a target enclave, and the source enclave and the target enclave each are used to provide a storage space required for running a corresponding program. The processing apparatus further comprises a storage access controller, adapted to transmit specified data stored in the source enclave to the target enclave. According to the processing apparatus, the embedded system, the system-on-chip, and the security control method provided in the embodiments of the present disclosure, a storage access controller can be used to implement a data transmission process from a source enclave to a target enclave, without requiring a processor for data transferring, thereby improving efficiency of inter-enclave data transmission while ensuring security.