Trust Domain Isolation via Token-Based Privilege Policies
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Information Handling Systems (IHS) face challenges in securely initializing and operating multiple trust domains within a secure execution environment, where unrelated entities require isolated operations and varying data security preferences, necessitating effective resource access control without significant overhead.
Innovation Solution
The implementation of methods and systems that retrieve and validate signing tokens and privilege policy tokens within a trusted component of the IHS, granting access to specific resources based on validated signatures, allowing for secure isolation of trust domains within a secure execution environment without requiring separate software enclaves like virtual machines or containers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If multiple unrelated entities operate within a single secure execution environment, then resource utilization is improved, but isolation and security control deteriorate
Solution Approach 1:
The patent segments the secure execution environment into multiple isolated trust domains, where each domain is assigned specific resources through privilege policy tokens. This allows multiple entities to operate concurrently with guaranteed isolation, resolving the contradiction between resource utilization and security control.
Solution Approach 2:
The patent implements local quality by assigning different privilege levels and resource access rights to different trust domains. Each domain receives customized resource allocation based on its specific security requirements, enabling both high resource utilization and tailored security control.
2Reliability
If separate software enclaves like virtual machines or containers are used for isolation, then security is improved, but system overhead increases
Solution Approach 1:
The patent merges the isolation functionality into the existing secure execution environment without requiring separate software enclaves. By using hardware-based trust domains and cryptographic tokens, it achieves isolation at the hardware level, eliminating the overhead of virtual machines or containers while maintaining strong security boundaries.
3Reliability
If strict resource access control is implemented for each trust domain, then security is improved, but resource allocation flexibility deteriorates
Solution Approach 1:
The patent implements dynamic resource allocation through privilege policy tokens that can be flexibly assigned and revoked. The system can dynamically adjust resource allocation for different trust domains based on security requirements and operational needs, maintaining both strict access control and high allocation flexibility.
Solution Approach 2:
The patent creates a universal privilege policy token mechanism that can be applied across all trust domains. This single framework supports multiple resource types and access control policies, providing both strict security control and versatile resource allocation capabilities through a unified system.
Data Source
AI summary
An established root of trust supports a secure execution environment (SEE) that supports execution of validated software instructions on behalf of trust domains that operate within the SEE to implement functions and to support hardware supported by the IHS. Embodiments support isolated operation of such trust domains within the SEE while avoiding the overhead of isolation within separate software environment enclaves. Signed instructions for the operation of a trust domain are retrieved and authenticated based on a signing token associated with the trust domain. If authenticated, the trust domain is granted access to resources set forth in a privilege policy token linked to the signing token of the trust domain. The privileges assigned to a trust domain may be modified by linking the trust domain's signing token to a new privilege policy token.


