Trusted Connection Protocol for TEE Peripheral Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Establishing trust between a trusted execution environment (TEE) and peripheral devices is complicated due to the large number of diverse peripherals and vendors, with existing solutions limited to software attacks, not supporting end-to-end protection, and not scaling well for multi-stream devices.
Innovation Solution
A new trusted connection protocol using Extensible Authentication Protocol (EAP) establishes an end-to-end trusted connection between any peripheral device and a TEE, leveraging authentication servers and attestation capabilities to create a secure connection independent of peripheral device vendors and physical connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing trust establishment solutions are used, then trust can be established between TEE and peripheral devices, but the complexity increases due to the large number and diversity of peripheral devices and vendors
Solution Approach 1:
The patent introduces an authentication server as an intermediary between the TEE and peripheral devices. The authentication server manages authentication credentials and performs verification, eliminating the need for the TEE to directly handle diverse authentication protocols from numerous peripheral device vendors. This mediator approach simplifies the TEE's trust establishment process while maintaining security across diverse device ecosystems.
Solution Approach 2:
The authentication server provides a universal authentication mechanism that works across all peripheral devices regardless of vendor or type. Instead of implementing multiple vendor-specific authentication solutions, the system uses a single universal authentication framework that handles diverse peripheral devices through standardized protocols, reducing complexity while maintaining broad compatibility.
2Reliability
If existing protection methods are used, then software attacks can be mitigated, but end-to-end protection is not achieved and hardware attacks remain vulnerable
Solution Approach 1:
The system performs preliminary authentication and credential verification before establishing trusted communication channels. The authentication server validates peripheral device credentials in advance, and the TEE verifies authentication results before enabling protected communication. This preliminary security action ensures that both software and hardware components are verified before trust is established, preventing both software and hardware attacks from the outset.
Solution Approach 2:
The patent combines multiple protection mechanisms into a unified end-to-end trusted connection framework. It merges authentication server verification, TEE attestation, encrypted communication channels, and hardware-peripheral verification into a single integrated security model. This combined approach provides comprehensive protection against both software and hardware attacks across the entire communication path.
3Adaptability or versatility
If traditional authentication protocols are used, then authentication can be performed, but scalability to all types of devices including multi-stream devices is limited
Solution Approach 1:
The authentication server implements a universal authentication framework that can handle multiple device types, communication protocols, and data streams through a single standardized interface. The system is designed to authenticate diverse peripheral devices (audio, video, storage, network) using consistent authentication mechanisms, enabling scalable deployment across expanding device ecosystems without requiring protocol-specific authentication implementations.
Solution Approach 2:
The system employs dynamic authentication capabilities that can adapt to different device types and communication scenarios in real-time. The authentication server can dynamically select appropriate authentication methods and credential verification processes based on the specific peripheral device being connected, enabling flexible scalability across diverse device categories including multi-stream devices while maintaining efficient authentication performance.
Data Source
AI summary
Technologies are provided in embodiments to establish trust between a trusted execution environment (TEE) and a peripheral device. Embodiments are configured to communicate with an attestation server to generate an encryption key, and to establish, using the encryption key, a secure connection with an authentication server to enable communication between the authentication server and the peripheral device. Embodiments are also configured to receive a pairwise master key if the peripheral device is authenticated and to receive a trusted communication from the peripheral device based, at least in part, on the pairwise master key. Embodiments may also be configured to identify a connection to the peripheral device before the peripheral device is authenticated to the authentication server, receive an identifier from the peripheral device, and establish a connection to an attestation server based on at least a portion of the identifier.


