TEE Integrity Measurement With Isolated Modules Against Tampering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional dynamic integrity measurement methods are vulnerable to attacks on the measurement module, compromising the reliability of integrity verification results due to the module's exposure and dependency on heavy-weight operating systems, which increases the attack surface and potential for tampering.
Innovation Solution
Implementing a lightweight TEE management module isolated from other components, performing integrity measurements through a trusted base, with validity verification and controlled access permissions to reduce the attack surface and ensure the module's security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a measurement module performs integrity verification on target objects, then integrity verification capability is provided, but the measurement module itself becomes vulnerable to attacks
Solution Approach 1:
The system is segmented into multiple trusted zones (first trusted zone, second trusted zone) with isolated measurement modules. Each zone has its own measurement module that operates independently, preventing a single point of failure and reducing the attack surface for any individual measurement module.
Solution Approach 2:
A TEE management module acts as an intermediary between the measurement modules and the target objects. This intermediary manages the measurement requests and coordinates the verification process, protecting the measurement modules from direct exposure to potential attacks while maintaining verification capability.
2Adaptability or versatility
If the measurement module depends on a heavy-weight TEE operating system, then functionality is enhanced, but the attack surface increases
Solution Approach 1:
The TEE functionality is segmented into a heavy-weight TEE operating system for general TEE applications and a lightweight management module for measurement operations. The measurement module in the first trusted zone depends on the lightweight management module rather than the full TEE operating system, reducing the attack surface while maintaining necessary functionality.
Solution Approach 2:
The measurement module extracts and depends only on the essential lightweight management module for its operations, separating the measurement functionality from the heavy-weight TEE operating system. This extraction reduces the dependency surface and minimizes potential attack vectors while preserving core measurement capabilities.
Data Source
AI summary
The disclosure provides an integrity measurement method, including two environments: a TEE and a non-TEE. The TEE includes a first trusted zone and a TEE management module. The first trusted zone is isolated from each component in the non-TEE and another trusted zone in the TEE. In other words, in a case of not being authorized, each component in the non-TEE and a component in the another trusted zone in the TEE do not have an access permission on a component in the first trusted zone. In embodiments of this application, a measurement module configured to perform integrity measurement is located in the first trusted zone, and performs an integrity measurement procedure by using a lightweight TEE management module as a trusted base.


