Trusted SEP Attestation for Secure Emulated Device Virtualization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In computing systems, man-in-the-middle (MITM) attacks can occur when a smart endpoint (SEP) or emulated SEP is used to spoof a PCIe device, leading to unauthorized access and data breaches, as existing security measures fail to ensure secure communication and authentication in virtualized environments.

Innovation Solution

Implementing a trusted SEP with attestation and authentication mechanisms, including cryptographic domains and unique identifiers, to form secure emulated devices that are assigned to trust domains, ensuring secure access and communication through attestation of hardware and firmware, and using encryption to protect data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If emulated devices are made accessible via device interface to virtual execution environments, then device utilization and virtualization efficiency are improved, but vulnerability to MITM attacks and unauthorized access increases

Engineering Contradiction:
Improvedevice utilizationVSAvoidMITM attack vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trust domain as an intermediary layer between the emulated device and the virtual execution environment. This trust domain acts as a mediator that verifies authentication credentials and manages access control, preventing direct unauthorized access while maintaining efficient device utilization through proper virtualization.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and attestation mechanisms before granting access to emulated devices. By performing verification of authentication credentials in advance through the trust domain, the system prevents MITM attacks before they can occur, while still allowing legitimate access to proceed efficiently.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication and attestation mechanisms are implemented for emulated devices, then security and protection against MITM attacks are improved, but system complexity and authentication overhead increase

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal trust domain architecture that handles multiple authentication and attestation functions through a single integrated mechanism. This trust domain can authenticate multiple emulated devices and manage various security credentials using a consistent framework, reducing overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent implements self-service authentication mechanisms where emulated devices automatically present their authentication credentials to the trust domain without requiring manual intervention. The trust domain autonomously verifies these credentials and manages access control, reducing the operational complexity of security management while maintaining high reliability.

Inventive Principle:
Principle #25Self-service

3Loss of information

If cryptographic domains and unique identifiers are used to secure emulated devices, then data integrity and identity protection are improved, but processing overhead and computational requirements increase

Engineering Contradiction:
Improvedata integrity protectionVSAvoidcomputational overhead
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent segments the security architecture into distinct cryptographic domains, each with its own unique identifier and encryption keys. By dividing the system into separate cryptographic zones, the patent enables targeted cryptographic operations only where needed, reducing overall computational overhead while maintaining data integrity and identity protection across the virtualized environment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230297410A1Device virtualization in a confidential computing environment
Publication Date: 2023.09.21 INTEL CORP
  • US20230297410A1 patent drawing
  • US20230297410A1 patent drawing
  • US20230297410A1 patent drawing

AI summary

Examples described herein relate to a trusted and secure emulated device. The emulated device can be assigned to a service based on attestation of a hardware platform of the emulated device, assignment of the emulated device to a trust domain, and attestation of a device configuration associated with the emulated device.