Trusted Execution Resource Manager for Shell TEE Pooling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Trusted Execution Environments (TEEs) in computer systems face challenges such as increased deployment latency due to validation processes across untrusted networks and inefficiencies in resource management, particularly in cloud computing environments where overcommitting resources leads to performance delays and reduced system availability.
Innovation Solution
A trusted execution resource manager establishes a launcher TEE instance in an untrusted host device, creating pools of shell TEEs with pre-configured basic run-time environments, allowing for efficient provisioning and reducing latency by selecting and provisioning a suitable TEE from these pools to service tenant requests.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TEE validation is performed across untrusted networks for each deployment, then security is improved, but deployment latency increases
Solution Approach 1:
The patent performs TEE validation and establishes trusted communication channels in advance before deployments occur. By pre-validating the TEE environment and creating pooled TEE instances with pre-established trust relationships, the system eliminates the need for time-consuming validation during each deployment, thus reducing deployment latency while maintaining security
Solution Approach 2:
The system pre-configures and pools TEE instances with basic run-time environments before tenant requests arrive. This preliminary preparation allows tenants to immediately provision applications onto pre-validated TEEs without waiting for validation during deployment, thereby reducing deployment latency while preserving security guarantees
2Productivity
If resources are overcommitted in cloud environments, then resource utilization is improved, but system availability decreases
Solution Approach 1:
The patent segments TEE resources into pooled instances with pre-configured basic run-time environments. By dividing the TEE resource pool into multiple pre-prepared instances, the system can allocate them efficiently to multiple tenants simultaneously, improving resource utilization while ensuring each segment maintains its security and availability independently
Solution Approach 2:
The system pre-configures basic run-time environments in pooled TEE instances before they are needed. This preliminary action ensures that when resources are allocated to multiple tenants, each TEE instance is already prepared and can immediately service tenant requests, thereby improving resource utilization without compromising system availability
3Productivity
If TEEs are started on demand, then resource efficiency is improved, but deployment latency increases
Solution Approach 1:
The patent pre-configures basic run-time environments in pooled TEE instances in advance, so when tenant requests arrive, the TEEs are already prepared and can be immediately provisioned. This eliminates the time-consuming setup process during on-demand deployment, reducing latency while maintaining resource efficiency through pooled management
Solution Approach 2:
The system dynamically manages pooled TEE instances, allowing them to be efficiently allocated and de-allocated based on tenant demands. The pooled architecture enables flexible resource distribution where pre-configured TEEs can be quickly assigned to different tenants as needed, improving both response time and resource efficiency
Data Source
AI summary
The technology disclosed herein enables resource sharing for trusted execution environments. An example method can include: establishing a first trusted execution environment (TEE) in a first computing device; establishing, by the first TEE, a set of shell TEEs, where each shell TEE is configured in view of one or more configuration parameters associated with the set of shell TEEs; receiving, by the first TEE, a request from a tenant computing device to establish a second TEE; determining, by the first TEE, whether the configuration parameters associated with the set of shell TEEs satisfy one or more request parameters for the second TEE; and responsive to determining that the configuration parameters associated with the set of shell TEEs satisfy the one or more request parameters for the second TEE, establishing, by the first TEE, the second TEE to satisfy the request, wherein the second TEE is selected from the set of shell TEEs, and causing, by the first TEE, the second TEE to communicate with tenant computing device.


