Storage Controller TEE Allocation for Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage technologies lack effective security isolation between applications and storage devices, relying on operating systems or hypervisors, which can be vulnerable to security threats and inefficient in providing secure storage spaces.

Innovation Solution

A host-storage system with multiple storage devices, where a first storage device provides resources for application execution and a second storage device allocates secure storage space in a Trusted Execution Environment (TEE) area based on application identification, physically isolating resources and data to ensure security without relying on specific OS or libraries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cloud and data center-based storage services expand and reduce dependence on operating systems or hypervisors, then security isolation between applications and storage devices is improved, but device complexity increases due to the need for application-level security management

Engineering Contradiction:
Improvesecurity isolationVSAvoidsecurity management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage device performs self-identification and self-allocation of secure storage spaces without requiring operating system or hypervisor intervention. The storage controller autonomously manages TEE area allocation based on application identification information, enabling security isolation without increasing system-level complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The storage device is divided into distinct functional areas: a first non-volatile memory for storing application execution resources and a second non-volatile memory for providing secure storage spaces in TEE area. This segmentation allows independent management of execution resources and secure data storage, simplifying security isolation mechanisms

Inventive Principle:
Principle #1Segmentation

2Reliability

If storage space is allocated in Trusted Execution Environment (TEE) area with physical isolation, then security against replay attacks and version rollback attacks is improved, but storage capacity availability is reduced

Engineering Contradiction:
Improvesecurity isolationVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The storage device is divided into distinct functional areas: a first non-volatile memory for storing application execution resources and a second non-volatile memory for providing secure storage spaces in TEE area. This segmentation allows independent management of execution resources and secure data storage, simplifying security isolation mechanisms

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different parts of the storage device have different functional properties: the first non-volatile memory provides resources for application execution while the second non-volatile memory provides secure storage with enhanced security properties. This local differentiation allows the system to maintain high storage capacity in the second memory while providing strong security isolation in the TEE area

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240184931A1Storage device, operating method thereof, and system for providing safe storage space between application and storage device on application-by-application basis
Publication Date: 2024.06.06 SAMSUNG ELECTRONICS CO LTD
  • US20240184931A1 patent drawing
  • US20240184931A1 patent drawing
  • US20240184931A1 patent drawing

AI summary

There is provided a method of operating a plurality of storage devices may include providing, by a first storage controller of a first storage device, resources required for execution of an application to a host device so that the host device executes the application; and allocating, by a second storage controller of a second storage device, a storage space to be used by the application executed in a trusted execution environment (TEE) area to the host device in units of applications based on identification information of the host device included in a allocation request.