Virtual Root of Trust Consolidation for Multi-Processor Secure Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed computing systems face security risks and manageability challenges due to the deployment of multiple physical ERoT chips across application processors, leading to increased costs, failure rates, and integration complexities, with ERoT chips having limited IO, code space, and memory protection capabilities.
Innovation Solution
Virtualization of ERoTs using a trusted execution environment within a management controller, such as a BMC, to consolidate security functions and eliminate the need for multiple ERoT chips, providing a centralized platform for secure boot, attestation, and policy enforcement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple physical ERoT chips are deployed across application processors, then security functions are provided for each AP, but device complexity and integration complexity increase
Solution Approach 1:
The patent consolidates multiple distributed ERoT chips into a single centralized ERoT chip that serves multiple application processors. This merging approach reduces the total number of security devices from many distributed chips to one centralized chip, thereby reducing integration complexity while maintaining security functions for all APs through a unified security management architecture
Solution Approach 2:
The centralized ERoT chip is designed to perform security functions for multiple different application processors simultaneously. It provides universal security services including secure boot, attestation, and policy enforcement across diverse AP types (GPUs, CPUs, DPUs), eliminating the need for dedicated ERoT chips for each processor type
2Reliability
If multiple ERoT chips are distributed across the system, then security coverage is provided for multiple APs, but the number of components and costs increase
Solution Approach 1:
The patent merges multiple individual ERoT chips into a single centralized security device that can serve multiple application processors. This consolidation reduces the quantity of security components from many distributed chips to one centralized chip, thereby reducing costs and component management overhead while maintaining comprehensive security coverage
Solution Approach 2:
The centralized ERoT chip is designed with multi-functional capabilities to provide security services to multiple different types of application processors (GPUs, CPUs, DPUs) simultaneously, replacing the need for multiple specialized ERoT chips with a single universal security device
3Reliability
If ERoT devices are deployed at network level, then network security is enhanced, but security policy distribution and enforcement becomes more challenging
Solution Approach 1:
The patent consolidates security policy management functions into a centralized ERoT chip that can uniformly distribute and enforce security policies across all application processors and network security appliances. This centralized approach simplifies policy management compared to distributing and managing policies across multiple distributed ERoT devices at different locations
Solution Approach 2:
The centralized ERoT chip implements unified security policy enforcement with centralized control, allowing security policies to be distributed from a single point and enforced consistently across all APs and network devices. This centralized feedback mechanism enables easier policy updates and enforcement compared to distributed policy management
Data Source
AI summary
A system includes a plurality of application processors (APs), a plurality of flash memory devices associated with the plurality of APs, and a plurality of multiplexers, each to selectively couple a flash memory device of the plurality of flash memory devices to an AP of the plurality of APs. A controller is operatively coupled to the plurality of multiplexers and provides a trusted execution environment to execute a virtual root of trust (vROT) application for each respective AP of the plurality of APs. Each vROT application accesses a corresponding one or more of the plurality of flash memory devices via a corresponding one or more of the plurality of multiplexers.


