Virtualized Security Domain for Low-Latency Multi-Domain TEE
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing Trusted Execution Environments (TEE) in multi-domain systems with high functional security demands lack sufficient functional security and fail to meet safety requirements, leading to performance overhead and latency issues, while existing solutions do not provide secure interfaces for multiple domains.
Innovation Solution
A separate security domain is established within a virtualized system, utilizing a hypervisor to manage hardware resources, with a middleware level providing a security execution environment that meets both safety and security requirements, allowing access to both security-related and non-security-related hardware resources, and employing flexible scheduling to ensure real-time responsiveness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TEE controls HW resources at highest privilege level, then security is enhanced, but performance overhead and latency increase
Solution Approach 1:
The system applies local quality by providing different execution environments tailored to specific needs: the security domain executes security-relevant applications with appropriate security measures, while other domains handle non-security applications without the overhead of security mechanisms. This localized approach reduces overall performance overhead while maintaining security where required.
2Reliability
If TEE runs within single domain, then security is maintained, but security interfaces for other domains are not provided
Solution Approach 1:
The security domain is designed with universal interfaces that enable it to interact with multiple other domains. The middleware level provides a security execution environment that can serve security-relevant applications across different domains, making the security infrastructure versatile and adaptable to various domain-specific requirements.
3Ease of manufacture
If open source software dependencies are used in TEE, then implementation is simplified, but maintenance burden increases
Solution Approach 1:
The system reduces maintenance burden by minimizing dependencies on external open source software. The security domain implements essential security functions with reduced reliance on external OSS components like ARM trusted firmware, thereby reducing the maintenance burden associated with OSS updates and security patches while maintaining implementation feasibility.
Data Source
AI summary
A system, security domain and method for providing a security execution environment for security-relevant, domain-specific applications in a virtualized system.

