Virtualized Trusted Descriptors for Secure Resource Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic systems lack effective mechanisms to securely manage and isolate access to sensitive resources among multiple security domains in virtualized environments, leading to potential unauthorized access to secret keys and other sensitive information.

Innovation Solution

The implementation of virtualized trusted descriptors, which are digitally signed with a security domain identifier, allowing only authorized operating systems to access specific resources, thereby separating and securing access to different security domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple security domains share access to cryptographic resources in a virtualized environment, then resource utilization efficiency is improved, but security isolation is compromised and unauthorized access to secret keys becomes possible

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity isolation
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments cryptographic resources by introducing security domain identifiers that partition access to cryptographic operations. Each security domain is assigned unique identifiers that restrict which descriptors can access which cryptographic resources, thereby maintaining security isolation while allowing multiple domains to utilize the same physical cryptographic hardware simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security domain identifiers as an intermediary mechanism between multiple security domains and cryptographic resources. These identifiers act as mediators that control and regulate access, ensuring that each domain can only access resources authorized for its security level, thus enabling secure shared access without compromising isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If trusted descriptors are made accessible to multiple operating systems, then system versatility is improved, but access control is weakened and unauthorized access to sensitive information becomes possible

Engineering Contradiction:
Improvesystem versatilityVSAvoidaccess control
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent applies local quality by associating specific security domain identifiers with specific descriptors and cryptographic resources. Each descriptor is tagged with security domain information that determines its accessible resource set, creating localized access control policies that enable versatile system operation while maintaining precise access control boundaries.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the access control parameter by incorporating security domain identifiers into the descriptor structure itself. This parameter change transforms descriptors from generic execution units into security-aware entities that automatically enforce access control based on their embedded security domain information, thereby maintaining ease of operation while enhancing security.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If cryptographic resources are shared among multiple security domains, then resource efficiency is improved, but the complexity of managing security isolation increases

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity isolation management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent achieves universality by designing a unified security domain identifier mechanism that handles access control for all cryptographic resources across all security domains. This single universal approach to security isolation management replaces multiple domain-specific control mechanisms, thereby reducing overall system complexity while enabling efficient resource sharing.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8826391B2Virtualized trusted descriptors
Publication Date: 2014.09.02 NXP USA INC
  • US8826391B2 patent drawing
  • US8826391B2 patent drawing
  • US8826391B2 patent drawing

AI summary

Embodiments of information processing systems and associated components can include logic operable to perform operations in a virtualized system including a plurality of guest operating systems using descriptors. The descriptors specify a set of commands defining the operations in a plurality of security domains and specify permission to a plurality of resources selectively for the plurality of guest operating systems.