Trust Domain Isolation via Token-Based Privilege Policies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHS) face challenges in securely initializing and operating multiple trust domains within a secure execution environment, where unrelated entities require isolated operations and varying data security preferences, necessitating effective resource access control without significant overhead.

Innovation Solution

The implementation of methods and systems that retrieve and validate signing tokens and privilege policy tokens within a trusted component of the IHS, granting access to specific resources based on validated signatures, allowing for secure isolation of trust domains within a secure execution environment without requiring separate software enclaves like virtual machines or containers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple unrelated entities operate within a single secure execution environment, then resource utilization is improved, but isolation and security control deteriorate

Engineering Contradiction:
Improveresource utilizationVSAvoidisolation security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the secure execution environment into multiple isolated trust domains, where each domain is assigned specific resources through privilege policy tokens. This allows multiple entities to operate concurrently with guaranteed isolation, resolving the contradiction between resource utilization and security control.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different privilege levels and resource access rights to different trust domains. Each domain receives customized resource allocation based on its specific security requirements, enabling both high resource utilization and tailored security control.

Inventive Principle:
Principle #3Local quality

2Reliability

If separate software enclaves like virtual machines or containers are used for isolation, then security is improved, but system overhead increases

Engineering Contradiction:
Improvetrust domain isolationVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the isolation functionality into the existing secure execution environment without requiring separate software enclaves. By using hardware-based trust domains and cryptographic tokens, it achieves isolation at the hardware level, eliminating the overhead of virtual machines or containers while maintaining strong security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If strict resource access control is implemented for each trust domain, then security is improved, but resource allocation flexibility deteriorates

Engineering Contradiction:
Improveresource access controlVSAvoidresource allocation flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic resource allocation through privilege policy tokens that can be flexibly assigned and revoked. The system can dynamically adjust resource allocation for different trust domains based on security requirements and operational needs, maintaining both strict access control and high allocation flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent creates a universal privilege policy token mechanism that can be applied across all trust domains. This single framework supports multiple resource types and access control policies, providing both strict security control and versatile resource allocation capabilities through a unified system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11102002B2Trust domain isolation management in secured execution environments
Publication Date: 2021.08.24 DELL PROD LP
  • US11102002B2 patent drawing
  • US11102002B2 patent drawing
  • US11102002B2 patent drawing

AI summary

An established root of trust supports a secure execution environment (SEE) that supports execution of validated software instructions on behalf of trust domains that operate within the SEE to implement functions and to support hardware supported by the IHS. Embodiments support isolated operation of such trust domains within the SEE while avoiding the overhead of isolation within separate software environment enclaves. Signed instructions for the operation of a trust domain are retrieved and authenticated based on a signing token associated with the trust domain. If authenticated, the trust domain is granted access to resources set forth in a privilege policy token linked to the signing token of the trust domain. The privileges assigned to a trust domain may be modified by linking the trust domain's signing token to a new privilege policy token.