Storage Controller TEE Allocation for Application Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage technologies lack effective security isolation between applications and storage devices, relying on operating systems or hypervisors, which can be vulnerable to security threats and inefficient in providing secure storage spaces.
Innovation Solution
A host-storage system with multiple storage devices, where a first storage device provides resources for application execution and a second storage device allocates secure storage space in a Trusted Execution Environment (TEE) area based on application identification, physically isolating resources and data to ensure security without relying on specific OS or libraries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud and data center-based storage services expand and reduce dependence on operating systems or hypervisors, then security isolation between applications and storage devices is improved, but device complexity increases due to the need for application-level security management
Solution Approach 1:
The storage device performs self-identification and self-allocation of secure storage spaces without requiring operating system or hypervisor intervention. The storage controller autonomously manages TEE area allocation based on application identification information, enabling security isolation without increasing system-level complexity
Solution Approach 2:
The storage device is divided into distinct functional areas: a first non-volatile memory for storing application execution resources and a second non-volatile memory for providing secure storage spaces in TEE area. This segmentation allows independent management of execution resources and secure data storage, simplifying security isolation mechanisms
2Reliability
If storage space is allocated in Trusted Execution Environment (TEE) area with physical isolation, then security against replay attacks and version rollback attacks is improved, but storage capacity availability is reduced
Solution Approach 1:
The storage device is divided into distinct functional areas: a first non-volatile memory for storing application execution resources and a second non-volatile memory for providing secure storage spaces in TEE area. This segmentation allows independent management of execution resources and secure data storage, simplifying security isolation mechanisms
Solution Approach 2:
Different parts of the storage device have different functional properties: the first non-volatile memory provides resources for application execution while the second non-volatile memory provides secure storage with enhanced security properties. This local differentiation allows the system to maintain high storage capacity in the second memory while providing strong security isolation in the TEE area
Data Source
AI summary
There is provided a method of operating a plurality of storage devices may include providing, by a first storage controller of a first storage device, resources required for execution of an application to a host device so that the host device executes the application; and allocating, by a second storage controller of a second storage device, a storage space to be used by the application executed in a trusted execution environment (TEE) area to the host device in units of applications based on identification information of the host device included in a allocation request.


