Trusted Domain Migration with Tenant-Specific TEE Readiness

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Migrating trusted domains in cloud computing environments is challenging due to security vulnerabilities, software bugs, and compromised hypervisors, which can disrupt the security and operation of resources, and unexpected migration failures can occur if the target resource is not prepared.

Innovation Solution

A cloud managed confidential resource migration strategy that includes defining a tenant-specific catalog, provisioning TEE hardware, monitoring configuration states, analyzing risks, and applying maintenance states to mitigate potential security risks, using tenant cluster health and resource configuration policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If trusted domain migration is performed in cloud environment, then resource flexibility and scalability are improved, but security vulnerabilities and hypervisor bugs can compromise security and operation

Engineering Contradiction:
Improveresource flexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the trusted domain migration process into distinct phases: pre-migration security validation, controlled migration execution, and post-migration verification. Each phase has independent security checks that isolate potential failure points, preventing a single vulnerability from compromising the entire migration process while maintaining resource flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hypervisor-agnostic security validation layer is introduced as an intermediary between the trusted domain and the underlying hypervisor infrastructure. This mediator validates security policies and isolates the trusted domain from hypervisor vulnerabilities, enabling secure migration across different hypervisor platforms without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hypervisor security is enhanced to protect trusted domains, then security is improved, but migration complexity and preparation requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidmigration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security validation framework is designed to be hypervisor-agnostic and can validate multiple trusted domain configurations simultaneously. This universal approach consolidates security checks into a single standardized process that works across different hypervisor types, reducing migration complexity while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Security validation and target resource preparation are performed in advance before migration execution. The system pre-validates security policies, checks target resource compatibility, and prepares migration pathways beforehand, which simplifies the actual migration process and reduces on-the-fly complexity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If target resource preparation is performed to ensure successful migration, then migration reliability is improved, but migration time and resource overhead increase

Engineering Contradiction:
Improvemigration reliabilityVSAvoidmigration time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security validation and resource preparation are performed continuously in the background before migration is requested, rather than being triggered by the migration event itself. This continuous preparation ensures resources are ready when needed without adding delay to the actual migration execution, maintaining both reliability and speed.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs target resource validation, security policy verification, and migration pathway preparation in advance and caches the results. When migration is initiated, the system reuses these pre-computed validations, significantly reducing the time required for actual migration while ensuring reliability through thorough prior preparation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12574418B2Confidential resource trusted domain migration strategy
Publication Date: 2026.03.10 DELL PROD LP
  • US12574418B2 patent drawing
  • US12574418B2 patent drawing
  • US12574418B2 patent drawing

AI summary

One example method includes receiving, from a prospective tenant, a request to provision a tenant cluster of a cloud computing environment, creating, and/or accessing, a tenant-specific catalog that contains information identifying a tenant-specific configuration of trusted execution environment (TEE) hardware, provisioning the TEE hardware according to the information in the tenant-specific catalog, monitoring the TEE hardware for any TEE state changes, analyzing a detected TEE state change, and when the detected TEE state change indicates a specified risk, applying a TEE hardware maintenance state to the TEE hardware.