IP Library Patent Application 11448920
Patent Application
App. No. 11/448,920

Method, device, and system of maintaining a context of a secure execution environment

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
11/448,920
Abstract

Some demonstrative embodiments of the invention include a method, device and/or system of maintaining a context of a secure execution environment. According to some demonstrative embodiments of the invention, the device may include a secure context processing module to receive a processed context from a first process operating in the secure execution environment; encrypt the processed context using a secret key maintained in the secure execution environment to generate an encrypted context; and provide the encrypted context to a second process operating in a non-secure execution environment. Other embodiments are described and claimed.

Claims (50)

1 . An apparatus having a secure execution environment and a non-secure execution environment, said apparatus comprising:

a secure context processing module to:

receive a processed context from a first process operating in said secure execution environment;

encrypt said processed context using a secret key maintained in said secure execution environment to generate an encrypted context; and

provide said encrypted context to a second process operating in said non-secure execution environment.

2 . The apparatus of claim 1 , wherein said context processing module decrypts a received context using said secret key to generate a decrypted context, said received process is received from a third process operating in said non-secure execution environment; and provides said decrypted context to a fourth process operating in said secure execution environment.

3 . The apparatus of claim 2 , wherein said received context comprises said encrypted context.

4 . The apparatus of claim 2 , wherein said third process comprises said second process.

5 . The apparatus of claim 2 , wherein said third process is different than said second process.

6 . The apparatus of claim 2 , wherein said fourth process comprises said first process.

7 . The apparatus of claim 2 , wherein said fourth process is different than said first process.

8 . The apparatus of claim 1 , wherein said context processing module generates authentication information corresponding to said processed context, and authenticates a context received from said non-secure execution environment based on said authentication information.

9 . The apparatus of claim 1 , wherein said context processing module generates integrity information corresponding to said processed context, and verifies the integrity of a context received from said non-secure execution environment based on said integrity information.

10 . The apparatus of claim 1 , wherein said context processing module generates session information identifying a session during which said encrypted context is generated, and verifies the session of a context received from said non-secure execution environment based on said session information.

11 . The apparatus of claim 1 , wherein said context processing module stores said encrypted context in a memory address associated with said non-secure execution environment.

12 . The apparatus of claim 1 , wherein said first process comprises at least part of a cryptographic process.

13 . The apparatus of claim 1 , wherein said context processing module operates in said secure execution environment.

14 . A method of maintaining one or more contexts of a secure execution, said method comprising:

receiving a processed context from a first process operating in said secure execution environment;

encrypting said processed context using a secret key maintained in said secure execution environment to generate an encrypted context; and

providing said encrypted context to a second process operating in a non-secure execution environment.

15 . The method of claim 14 comprising:

receiving from a third process operating in said non-secure execution environment a received context;

decrypting said received context using said secret key to generate a decrypted context; and

providing said decrypted context to a fourth process operating in said secure execution environment.

16 . The method of claim 15 , wherein receiving said received context comprises receiving said encrypted context.

17 . The method of claim 15 , wherein receiving said received context comprises receiving said received context from a process comprising said second process.

18 . The method of claim 15 , wherein receiving said received context comprises receiving said received context from a process different than said second process.

19 . The method of claim 15 , wherein providing said decrypted context comprises providing said decrypted context to a process comprising said first process.

20 . The method of claim 15 , wherein providing said decrypted context comprises providing said decrypted context to a process different than said first process.

21 . The method of claim 14 comprising:

generating authentication information corresponding to said processed context; and

authenticating a context received from said non-secure execution environment based on said authentication information.

22 . The method of claim 14 comprising:

generating integrity information corresponding to said processed context; and

ensuring the integrity of a context received from said non-secure execution environment based on said integrity information.

23 . The method of claim 14 comprising:

generating session information identifying a session during which said context is encrypted; and

verifying a session of a context received from said non-secure execution environment based on said session information.

24 . The method of claim 14 comprising storing said encrypted context in a memory address associated with said non-secure execution environment.

25 . The method of claim 14 , wherein receiving said processed context comprises receiving said processed context from a cryptographic process.

26 . The method of claim 14 , comprising performing said receiving, encrypting and providing in said secure execution environment.

27 . A computing system comprising:

a secure context processing module to:

receive a processed context from a first process operating in a secure execution environment;

encrypt said processed context using a secret key maintained in said secure execution environment to generate an encrypted context; and

provide said encrypted context to a second process operating in a non-secure execution environment; and

a memory to store said encrypted context.

28 . The system of claim 27 , wherein said context processing module decrypts a received context using said secret key to generate a decrypted context, said received process is received from a third process operating in said non-secure execution environment; and provides said decrypted context to a fourth process operating in said secure execution environment.

29 . The system of claim 27 , wherein said context processing module generates session information identifying a session during which said encrypted context is generated, and verifies the session of a context received from said non-secure execution environment based on said session information ( Session information is embedded in the encrypted context).

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 19, 2017
From: ARM TECHNOLOGIES ISRAEL LIMITED
To: ARM LIMITED
Reel/Frame 043906/0343 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2007
From: GREENSPAN, RONEN
To: DISCRETIX TECHNOLOGIES LTD.
Reel/Frame 018820/0277 →