TEE-IO Device Security Manager for Direct Trusted VM Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trust domain technologies, such as TDX 1.0, do not support direct and trusted input/output operations for integrated devices, leading to performance overheads and limitations in functionality and security due to the need for software-based encryption and lack of support for advanced IO virtualization models.

Innovation Solution

A device security manager architecture that enables direct and trusted input/output operations without requiring encrypted messages, simplifying the implementation and reducing costs by eliminating the need for cryptographic engines and message processors, while maintaining security and functional requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based protection mechanisms are used for IO operations between trust domains and IO devices, then security is maintained, but performance overhead increases and direct IO is not supported

Engineering Contradiction:
ImprovesecurityVSAvoidperformance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the IO protection functionality by introducing a dedicated Device Security Manager (DSM) component that handles security operations separately from the main trust domain management. This segmentation allows direct IO operations to proceed through hardware-enforced security boundaries without requiring software-based protection mechanisms, thereby maintaining security while eliminating performance overhead.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The Device Security Manager acts as an intermediary between trust domains and IO devices, providing hardware-enforced security for direct IO operations. This intermediary component enables trusted IO by mediating access through dedicated security circuits rather than software-based protection, resolving the contradiction between security and performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encrypted messages and cryptographic engines are used for secure IO communications, then security requirements are met, but device complexity and overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the cryptographic engine and message processor requirements from the Device Security Manager for integrated devices. By removing these complex components and relying on hardware-enforced security boundaries and trusted device interfaces, the system meets security requirements while significantly reducing device complexity and overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent employs simpler, lighter-weight security mechanisms that do not require expensive cryptographic engines. The security model uses hardware-enforced boundaries and trusted interfaces that are less complex than full cryptographic stacks, achieving security with reduced device complexity.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If TDX 1.0 trust domain technology is used, then hardware isolation of virtual machines is achieved, but direct IO support and advanced IO virtualization are limited

Engineering Contradiction:
Improvehardware isolationVSAvoidIO virtualization support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces dynamic IO assignment capabilities through the Device Security Manager, allowing trust domains to dynamically access and control IO devices. This dynamic mechanism enables advanced IO virtualization models while maintaining the hardware isolation provided by TDX 1.0, thereby increasing adaptability without sacrificing security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The Device Security Manager serves as an intermediary that enables advanced IO virtualization while preserving hardware isolation. It provides the necessary security framework for direct IO and virtualization extensions, allowing TDX 1.0 systems to support modern IO models without compromising the trusted execution environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4216089B1Device security manager architecture for trusted execution environment input/output (TEE-IO) capable system-on-a-chip integrated devices
Publication Date: 2026.05.06 INTEL CORP
  • EP4216089B1 patent drawingFigure 1
  • EP4216089B1 patent drawingFigure 2
  • EP4216089B1 patent drawingFigure 3

AI summary

Systems, methods, and apparatuses for implementing device security manager architecture for trusted execution environment input/output (TEE-IO) capable system-on-a-chip integrated devices are described. In one example, a system includes a hardware processor core configurable to implement a trust domain manager to manage one or more virtual machines as a respective trust domain isolated from a virtual machine monitor, and an input/output device coupled to the hardware processor core and comprising a device security manager circuit, wherein the device security manager circuit is to, in response to an trusted request from the trust domain manager to a control interface of the device security manager circuit, access a state of a trusted device interface of the input/output device for a trust domain of the trust domain manager, and provide a corresponding response to the trust domain manager.