Trusted SEP Attestation for Secure Emulated Device Virtualization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In computing systems, man-in-the-middle (MITM) attacks can occur when a smart endpoint (SEP) or emulated SEP is used to spoof a PCIe device, leading to unauthorized access and data breaches, as existing security measures fail to ensure secure communication and authentication in virtualized environments.
Innovation Solution
Implementing a trusted SEP with attestation and authentication mechanisms, including cryptographic domains and unique identifiers, to form secure emulated devices that are assigned to trust domains, ensuring secure access and communication through attestation of hardware and firmware, and using encryption to protect data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If emulated devices are made accessible via device interface to virtual execution environments, then device utilization and virtualization efficiency are improved, but vulnerability to MITM attacks and unauthorized access increases
Solution Approach 1:
The patent introduces a trust domain as an intermediary layer between the emulated device and the virtual execution environment. This trust domain acts as a mediator that verifies authentication credentials and manages access control, preventing direct unauthorized access while maintaining efficient device utilization through proper virtualization.
Solution Approach 2:
The patent implements preliminary authentication and attestation mechanisms before granting access to emulated devices. By performing verification of authentication credentials in advance through the trust domain, the system prevents MITM attacks before they can occur, while still allowing legitimate access to proceed efficiently.
2Reliability
If authentication and attestation mechanisms are implemented for emulated devices, then security and protection against MITM attacks are improved, but system complexity and authentication overhead increase
Solution Approach 1:
The patent creates a universal trust domain architecture that handles multiple authentication and attestation functions through a single integrated mechanism. This trust domain can authenticate multiple emulated devices and manage various security credentials using a consistent framework, reducing overall system complexity while maintaining comprehensive security.
Solution Approach 2:
The patent implements self-service authentication mechanisms where emulated devices automatically present their authentication credentials to the trust domain without requiring manual intervention. The trust domain autonomously verifies these credentials and manages access control, reducing the operational complexity of security management while maintaining high reliability.
3Loss of information
If cryptographic domains and unique identifiers are used to secure emulated devices, then data integrity and identity protection are improved, but processing overhead and computational requirements increase
Solution Approach 1:
The patent segments the security architecture into distinct cryptographic domains, each with its own unique identifier and encryption keys. By dividing the system into separate cryptographic zones, the patent enables targeted cryptographic operations only where needed, reducing overall computational overhead while maintaining data integrity and identity protection across the virtualized environment.
Data Source
AI summary
Examples described herein relate to a trusted and secure emulated device. The emulated device can be assigned to a service based on attestation of a hardware platform of the emulated device, assignment of the emulated device to a trust domain, and attestation of a device configuration associated with the emulated device.


