Trusted Execution Environment Factory Data Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Factory data on mobile platforms is often lost or rendered untrustworthy when the operating system is changed, forcing costly re-calibrations or preventing OS migrations.
Innovation Solution
A root-of-trust apparatus provides an OS-independent solution for provisioning and maintaining factory data in non-volatile memory, using a trusted execution environment to organize and secure data across OS updates and migrations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If factory data is stored using OS-specific provisioning formats in non-volatile memory, then the data can be properly managed and accessed by the current operating system, but the data is lost or rendered untrustworthy when the operating system is changed or migrated
Solution Approach 1:
The patent segments the data storage system into two independent parts: a trusted execution environment (TEE) that maintains OS-independent factory data, and the host operating system that runs application-specific code. The TEE creates a separate secure data store that is isolated from OS-specific file systems and provisioning formats, allowing factory data to be preserved during OS migrations while still being accessible when needed.
Solution Approach 2:
The trusted execution environment acts as an intermediary layer between the host operating system and the non-volatile memory storage. This TEE intermediary manages factory data using OS-independent formats and protocols, translating between different OS requirements and a universal secure storage format, thereby enabling OS migrations without data loss while maintaining data integrity for the host system.
2Ease of operation
If factory data is stored in shared non-volatile memory with OS-specific partitions, then the operating system can efficiently access and manage the data, but re-configuring the platform to run a different OS results in data loss or corruption
Solution Approach 1:
The patent segments the non-volatile memory into distinct regions: a secure TEE-managed portion for OS-independent factory data with its own provisioning format, and separate host OS file system partitions. This segmentation allows the TEE to maintain efficient access to factory data through dedicated secure protocols while the host OS maintains its own efficient access paths to its data, and enables OS reconfiguration without affecting the TEE-protected factory data.
Solution Approach 2:
The trusted execution environment provides a universal data storage interface that can serve multiple operating systems and configurations. The TEE implements OS-independent provisioning formats and data management protocols that work across different OS types and versions, making the factory data store universally accessible and adaptable while maintaining efficient access patterns similar to OS-specific solutions.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
Systems, apparatuses and methods may provide for receiving, from a host driver, factory data including one or more of calibration data, platform identifier data, manufacturer data or wireless carrier data, and verifying integrity of the factory data. Additionally, the factory data may be provisioned into non-volatile memory (NVM) in accordance with an operating system independent format managed by a platform root-of-trust such as a Trusted Execution Environment (TEE). In one example, provisioning the factory data includes defining one or more partitions in the NVM, initiating storage of the factory data to the NVM along the one or more partitions, and specifying a restriction profile for the one or more partitions, wherein the restriction profile includes one or more of read restrictions, write restrictions, time bound restrictions or location bound restrictions.