Hybrid device with trusted execution environment
Inventors
Ng, Chi Wai • LAM, Chan Fai • Lee, Yun Kau
Assignees
Hong Kong Applied Science and Technology Research Institute ASTRI
Interested in licensing this patent?
MTEC can help explore whether this patent might be available for licensing for your application.
Abstract
A Hybrid TEE device allows a Trusted Execution Environment (TEE) by incorporating hardware comprising a Cache Purging Controller, a Memory Isolation Gateway, and a Memory Clean Up into a System on a Chip device, a general purpose computing device, or a special purpose or proprietary computing or electronic device. The addition of the hardware enables a method of protecting the Trusted Execution Environment and thus reducing vulnerability to malicious software or other program code.
Core Innovation
The invention describes a hybrid device with a trusted execution environment (TEE) implemented using dedicated hardware components. The hybrid device includes a processor core with a cache purging controller, a memory controller communicating with the processor and physical memory, and one or more peripherals that communicate with the processor core. The TEE subsystem includes memory mapped registers, a memory isolation gateway, and a memory clean up, where the TEE subsystem controls communication between the processor core and the memory controller and/or the peripherals.
The invention further addresses secure isolation for execution by using trusted and non-trusted virtual processing cells. A trusted processing cell and at least one non-trusted processing cell are defined and run on a processor, and at least two virtual memory cells are defined corresponding to areas of a physical memory device. The memory isolation gateway stores memory cell configurations and assigns virtual memory cells to virtual processing cells so that access attempts by the processor are checked for correspondence to the assigned relationship.
The invention also describes hardware-software hybrid cell switching in which a trusted processing cell executes an interrupt handler to perform cache purging and memory clean-up before selecting and switching to a new cell. Cell switching functions include system services, inter-cell communication and checking cell pending events. After performing a memory return instruction to the selected new cell, the instructions provided by the selected new cell are executed, with access mediated through the memory isolation gateway.
An alternate embodiment allows the cache purging controller, memory isolation gateway, and memory clean up to be implemented as external modules for retrofit and/or upgrades, rather than being fully integrated. The device is described as implementable in a SoC and/or other general-purpose or specialized computing platform, including trusted and non-trusted virtual processing cells operating with cell switching mediated by the trusted execution environment.
Claims Coverage
The independent claims include three core inventive areas: (i) a hybrid TEE device architecture, (ii) a gateway-mediated virtual memory access control method, and (iii) a hardware-software cell switching method that includes cache purging and memory clean-up in a trusted processing cell. Across the independent claims, the inventive features center on cache purging controller, memory isolation gateway, memory clean up, and virtual processing cell/virtual memory cell mapping under trusted execution.
Hybrid trusted execution environment device architecture with controlled communication
A hybrid device with trusted execution environment comprising a processor core with a cache purging controller; a memory controller communicating with the processor and physical memory; one or more peripherals comprising one or more of a general purpose input output controller, a flash memory, or a universal asynchronous receiver-transmitter, the peripherals communicating with the processor core; and a trusted execution environment (TEE) subsystem comprising memory mapped registers, a memory isolation gateway and a memory clean up, the TEE subsystem controlling all communication between the processor core and the memory controller and/or the peripherals.
Gateway-mediated virtual memory access check for trusted and non-trusted processing cells
A method of hardware-software hybrid device with trusted execution environment operation comprising defining at least two virtual processing cells including a trusted processing cell and at least one non-trusted processing cells, defining at least two virtual memory cells corresponding to at least two areas of a physical memory device according to memory cell configurations stored in a memory isolation gateway, assigning one of the virtual memory cells to each of the virtual processing cells, monitoring the processor for attempts to access the virtual memory cells due to instructions from one of the virtual processing cells, checking via the memory isolation gateway to ensure that the virtual memory cell being accessed by the processor corresponds to the virtual memory cell assigned to the virtual processing cell which provided the instruction, permitting access if the virtual memory cell corresponds and returning to the monitoring step otherwise blocking via the memory isolation gateway the attempt to access the virtual memory cell and returning an error indicating that the attempt to access the memory was unsuccessful.
Trusted-cell interrupt handler driven cell switching with cache purge and memory clean-up
A method of hardware-software hybrid cell switching comprising defining at least two virtual processing cells including a trusted processing cell and at least one non-trusted processing cell, the new cell being selected from one of the virtual processing cells; defining at least two virtual memory cells corresponding to at least two areas of a physical memory device according to memory cell configurations stored in a memory isolation gateway; assigning one of the virtual memory cells to each of the virtual processing cells; monitoring the processor for attempts to access the virtual memory cells due to instructions from one of the virtual processing cells; checking via the memory isolation gateway to ensure correspondence between the accessed virtual memory cell and the assigned virtual processing cell that provided the instruction; permitting access if correspondence exists otherwise blocking via the memory isolation gateway and returning an error; setting up a timer in a processor to trigger an interrupt; entering an interrupt handler running in a trusted processing cell; setting a code register to a location of cell code; setting a new cell register to the location of a selected new cell; setting a cache purge flag to true; executing a cache purging operation with a cache purging controller; setting the cache purge flag to false; defining a memory clean-up starting address and a memory clean-up ending address to define a memory clean-up range; setting a memory clean-up flag to true; performing a memory clean-up operation on the memory clean-up range with a memory clean-up; performing cell switching functions including system services, inter-cell communication and checking cell pending events; executing a memory return instruction to the selected new cell; and executing the instructions provided by the selected new cell.
Across the independent claims, the coverage is directed to a hybrid device TEE subsystem that includes memory mapped registers, memory isolation gateway, and memory clean up with a cache purging controller in a processor core, and methods that enforce correct virtual memory access by checking correspondence between accessed virtual memory cells and assigned virtual processing cells via the memory isolation gateway, including trusted processing cell interrupt handling to set cell code/new cell registers and perform cache purging and memory clean-up prior to executing the selected new cell’s instructions.
Stated Advantages
Not explicitly described in patent.
Documented Applications
Not explicitly described in patent.
Interested in licensing this patent?