Virtualized Security Domain for Low-Latency Multi-Domain TEE

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Trusted Execution Environments (TEE) in multi-domain systems with high functional security demands lack sufficient functional security and fail to meet safety requirements, leading to performance overhead and latency issues, while existing solutions do not provide secure interfaces for multiple domains.

Innovation Solution

A separate security domain is established within a virtualized system, utilizing a hypervisor to manage hardware resources, with a middleware level providing a security execution environment that meets both safety and security requirements, allowing access to both security-related and non-security-related hardware resources, and employing flexible scheduling to ensure real-time responsiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TEE controls HW resources at highest privilege level, then security is enhanced, but performance overhead and latency increase

Engineering Contradiction:
ImprovesecurityVSAvoidperformance overhead
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies local quality by providing different execution environments tailored to specific needs: the security domain executes security-relevant applications with appropriate security measures, while other domains handle non-security applications without the overhead of security mechanisms. This localized approach reduces overall performance overhead while maintaining security where required.

Inventive Principle:
Principle #3Local quality

2Reliability

If TEE runs within single domain, then security is maintained, but security interfaces for other domains are not provided

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity interfaces for multiple domains
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security domain is designed with universal interfaces that enable it to interact with multiple other domains. The middleware level provides a security execution environment that can serve security-relevant applications across different domains, making the security infrastructure versatile and adaptable to various domain-specific requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If open source software dependencies are used in TEE, then implementation is simplified, but maintenance burden increases

Engineering Contradiction:
Improveimplementation simplicityVSAvoidmaintenance burden
Core Design Contradiction:
Ease of manufactureVSEase of repair

Solution Approach 1:

The system reduces maintenance burden by minimizing dependencies on external open source software. The security domain implements essential security functions with reduced reliance on external OSS components like ARM trusted firmware, thereby reducing the maintenance burden associated with OSS updates and security patches while maintaining implementation feasibility.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12430158B2Method, system and domain for providing a security execution environment for security-relevant applications
Publication Date: 2025.09.30 ROBERT BOSCH GMBH
  • US12430158B2 patent drawing
  • US12430158B2 patent drawing

AI summary

A system, security domain and method for providing a security execution environment for security-relevant, domain-specific applications in a virtualized system.