Telemetry Filtering Circuitry for Secure Platform Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a conflict between the requirement of confidentiality in trusted execution environments and the need for telemetry data collection for platform monitoring, particularly due to side channel leakage through out-of-band telemetry data processing.
Innovation Solution
The solution involves extending trusted execution awareness from the core to the shared or "uncore" region of the processor, where a security policy is defined to control the reporting of telemetry data collected from trusted execution environments. This includes filtering telemetry data using a tainted packet counter and applying a telemetry class tier to determine the level of exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If telemetry data is collected from trusted execution environments for platform monitoring, then platform monitoring capability is improved, but security confidentiality is compromised due to side channel leakage
Solution Approach 1:
The patent segments telemetry data into different types (performance telemetry vs. confidential telemetry) and applies different handling rules to each segment. Performance telemetry can be collected and reported, while confidential telemetry is filtered out when generated during trusted execution environment operation, thus resolving the contradiction between monitoring capability and security confidentiality.
Solution Approach 2:
The patent introduces an intermediary mechanism (the out-of-order core telemetry filter) that sits between the telemetry generation source and the telemetry reporting path. This filter intermediates by examining the execution context and blocking confidential telemetry from being reported when TEE is active, while allowing performance telemetry to pass through, thus protecting against side channel leakage while maintaining monitoring capability.
2Loss of information
If all telemetry data is collected and reported, then monitoring completeness is improved, but security risk increases due to potential exposure of sensitive information
Solution Approach 1:
The patent applies local quality by making the telemetry filtering behavior context-dependent. The filter examines the local execution context (whether the core is operating in TEE mode) and applies different quality rules locally: when TEE is active, confidential telemetry is filtered out; when TEE is inactive, all telemetry can be collected. This resolves the contradiction by adapting the monitoring completeness vs. security risk balance to local conditions.
Solution Approach 2:
The patent performs preliminary action by pre-configuring security policies and filters before telemetry data is generated. The system预先 establishes rules about which telemetry types are confidential and configures the filter mechanism in advance, so that when telemetry is generated during TEE operation, the filtering decision is already determined, preventing security risks before they can materialize while maintaining monitoring completeness for non-sensitive data.
Data Source
AI summary
An apparatus and method for secure platform monitoring. For example, one embodiment of a processor comprises: a plurality of processing cores to execute instructions in different execution contexts, including a trusted execution context associated with a trusted execution environment; telemetry aggregation circuitry to aggregate telemetry data associated with one or more of the different execution contexts; a filter to prevent telemetry data associated with the trusted execution context from being aggregated by the telemetry aggregator; and an interface to communicate the telemetry data aggregated by the telemetry aggregation circuitry to an external agent.


