Trusted Execution Environment for Secure Network Booting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern computing environments face challenges in securely updating computing devices external to a trusted network due to intermittent connectivity, high error rates, and low bandwidth, making it difficult to access and distribute protected content such as executable images across untrusted networks.
Innovation Solution
A computing device external to the trusted network is used as a data exchange device with a trusted execution environment (TEE) to store and distribute protected content, employing hardware-based encryption to isolate data from other processes and enable secure data retrieval and distribution without exposing it to the operating system, even if compromised.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a computing device external to the trusted network is used as a data exchange device to store and distribute protected content, then the ability to distribute protected content across untrusted networks is improved, but the security risk increases because the device and network are untrusted
Solution Approach 1:
A trusted execution environment (TEE) is introduced as an intermediary between the untrusted data exchange device and the protected content. The TEE isolates the content in a secure enclave, allowing the device to distribute content without exposing it to the untrusted operating system or network, thus resolving the security risk while maintaining distribution capability
Solution Approach 2:
The computing device is segmented into two distinct parts: an untrusted operating system that handles network communication and a trusted execution environment that securely stores and manages protected content. This segmentation allows the system to operate in untrusted networks while maintaining security through the isolated TEE
2Reliability
If hardware-based encryption is used to isolate data in the trusted execution environment, then data confidentiality and integrity are improved, but device complexity increases
Solution Approach 1:
The trusted execution environment is implemented as a self-contained secure enclave that automatically handles encryption, decryption, and data isolation without requiring manual configuration or complex external security infrastructure. The TEE uses hardware-accelerated cryptography to provide security services autonomously, reducing operational complexity while maintaining high reliability
Data Source
AI summary
The technology disclosed herein enables a computing device to use a trusted execution environment in an untrusted device to distribute executable image data (e.g., network bootable image) to a set of one or more computing devices. An example method may include: establishing, by a processor, the trusted execution environment in a first computing device, wherein the trusted execution environment comprises an encrypted memory area; loading executable code into the trusted execution environment, wherein the executable code controls access to protected content and wherein the protected content comprises executable image data; and causing the executable code to execute in the trusted execution environment to analyze data of a second computing device and to provide the second computing device access to the protected content.


