IP Library › Granted Patent US 12,591,660
Granted Patent B2
US 12,591,660 · App. 18/154,334 · Granted Mar 31, 2026

Device security manager architecture for trusted execution environment input/output (TEE-IO) capable system-on-a-chip integrated devices

Inventors: Utkarsh Y. Kakaiya (El Dorado Hills, CA); Jiewen Yao (Shanghai, CN)
Assignee: Intel Corporation
G06F21/53G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,591,660
App. No.
18/154,334
Granted
Mar 31, 2026
Kind
B2
Abstract

Systems, methods, and apparatuses for implementing device security manager architecture for trusted execution environment input/output (TEE-IO) capable system-on-a-chip integrated devices are described. In one example, a system includes a hardware processor core configurable to implement a trust domain manager to manage one or more virtual machines as a respective trust domain isolated from a virtual machine monitor, and an input/output device coupled to the hardware processor core and comprising a device security manager circuit, wherein the device security manager circuit is to, in response to an trusted request from the trust domain manager to a control interface of the device security manager circuit, access a state of a trusted device interface of the input/output device for a trust domain of the trust domain manager, and provide a corresponding response to the trust domain manager.

Claims (44)

1 . An apparatus comprising:

a hardware processor core configurable to implement a trust domain manager to manage one or more virtual machines as a respective trust domain isolated from a virtual machine monitor; and

a device security manager circuit to be coupled between the hardware processor core and an input/output device, wherein the device security manager circuit is to, in response to a trusted request from the trust domain manager to a control interface of the device security manager circuit, access a state of a trusted device interface of the input/output device for a trust domain of the trust domain manager, and provide a corresponding response to the trust domain manager.

2 . The apparatus of claim 1 , wherein the control interface of the device security manager circuit comprises a set of one or more protected registers that are accessible by the trust domain manager and not accessible by the virtual machine monitor of the one or more virtual machines.

3 . The apparatus of claim 1 , wherein the control interface of the device security manager circuit comprises a protected trust domain mode and a management trusted device interface of the device security manager circuit, and the device security manager circuit is to access the state of the trusted device interface of the input/output device in response to the protected trust domain mode being enabled and the trusted request including a trusted execution environment field that indicates the trusted request is from a trusted entity.

4 . The apparatus of claim 3 , wherein the management trusted device interface of the device security manager circuit is accessible by the trust domain and not accessible by a second trust domain managed by the trust domain manager.

5 . The apparatus of claim 3 , wherein the management trusted device interface of the device security manager circuit is to not accept the trusted request in response to the protected trust domain mode being disabled.

6 . The apparatus of claim 5 , wherein the device security manager circuit is to:

lock configuration of the input/output device in response to the protected trust domain mode being enabled;

monitor the input/output device for a re-configuration or an error event;

disable the protected trust domain mode in response to the re-configuration; and

disable the protected trust domain mode in response to the error event.

7 . The apparatus of claim 1 , wherein the control interface of the device security manager circuit comprises a set of protected registers that provide firmware measurements for the input/output device.

8 . The apparatus of claim 1 , wherein the device security manager circuit is to, in response to the trusted request from the trust domain manager to the control interface of the device security manager circuit, transition the state of the trusted device interface according to a Trusted Execution Environment (TEE) Device Interface Security Protocol standard.

9 . A method comprising:

managing one or more virtual machines as a respective trust domain, isolated from a virtual machine monitor, by a trust domain manager implemented by a hardware processor core;

sending a trusted request from the trust domain manager to a control interface of a device security manager circuit of an input/output device coupled to the hardware processor core;

accessing, in response to the trusted request, a state of a trusted device interface of the input/output device for a trust domain of the trust domain manager; and

receiving a corresponding response by the trust domain manager.

10 . The method of claim 9 , wherein the control interface of the device security manager circuit comprises a set of one or more protected registers that are accessible by the trust domain manager and not accessible by the virtual machine monitor of the one or more virtual machines, and the receiving comprises performing a read or a write on the set of one or more protected registers.

11 . The method of claim 9 , wherein the control interface of the device security manager circuit comprises a protected trust domain mode and a management trusted device interface of the device security manager circuit, and the accessing the state of the trusted device interface of the input/output device is in response to the protected trust domain mode being enabled and the trusted request including a trusted execution environment field that indicates the trusted request is from a trusted entity.

12 . The method of claim 11 , wherein the management trusted device interface of the device security manager circuit is accessible by the trust domain and not accessible by a second trust domain managed by the trust domain manager.

13 . The method of claim 11 , further comprising not accepting, by the management trusted device interface of the device security manager circuit, the trusted request in response to the protected trust domain mode being disabled.

14 . The method of claim 13 , further comprising:

locking configuration of the input/output device in response to the protected trust domain mode being enabled;

monitoring the input/output device for a re-configuration or an error event;

disabling the protected trust domain mode in response to the re-configuration; and

disabling the protected trust domain mode in response to the error event.

15 . The method of claim 9 , wherein the control interface of the device security manager circuit comprises a set of protected registers, and the accessing comprises performing a read of firmware measurements from the set of protected registers for the input/output device.

16 . The method of claim 9 , wherein the accessing the state comprises transitioning the state of the trusted device interface according to a Trusted Execution Environment (TEE) Device Interface Security Protocol standard.

17 . A system comprising:

a hardware processor core configurable to implement a trust domain manager to manage one or more virtual machines as a respective trust domain isolated from a virtual machine monitor; and

an input/output device coupled to the hardware processor core and comprising a device security manager circuit, wherein the device security manager circuit is to, in response to a trusted request from the trust domain manager to a control interface of the device security manager circuit, access a state of a trusted device interface of the input/output device for a trust domain of the trust domain manager, and provide a corresponding response to the trust domain manager.

18 . The system of claim 17 , wherein the control interface of the device security manager circuit comprises a set of one or more protected registers that are accessible by the trust domain manager and not accessible by the virtual machine monitor of the one or more virtual machines.

19 . The system of claim 17 , wherein the control interface of the device security manager circuit comprises a protected trust domain mode and a management trusted device interface of the device security manager circuit, and the device security manager circuit is to access the state of the trusted device interface of the input/output device in response to the protected trust domain mode being enabled and the trusted request including a trusted execution environment field that indicates the trusted request is from a trusted entity.

20 . The system of claim 19 , wherein the management trusted device interface of the device security manager circuit is accessible by the trust domain and not accessible by a second trust domain managed by the trust domain manager.

21 . The system of claim 19 , wherein the management trusted device interface of the device security manager circuit is to not accept the trusted request in response to the protected trust domain mode being disabled.

22 . The system of claim 21 , wherein the device security manager circuit is to:

lock configuration of the input/output device in response to the protected trust domain mode being enabled;

monitor the input/output device for a re-configuration or an error event;

disable the protected trust domain mode in response to the re-configuration; and

disable the protected trust domain mode in response to the error event.

23 . The system of claim 17 , wherein the control interface of the device security manager circuit comprises a set of protected registers that provide firmware measurements for the input/output device.

24 . The system of claim 17 , wherein the device security manager circuit is to, in response to the trusted request from the trust domain manager to the control interface of the device security manager circuit, transition the state of the trusted device interface according to a Trusted Execution Environment (TEE) Device Interface Security Protocol standard.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2023
From: KAKAIYA, UTKARSH Y.; YAO, JIEWEN
To: INTEL CORPORATION
Reel/Frame 062428/0868 →
Priority Claims (1)
WO PCT/CN2022/072494 · Jan 18, 2022 · international
Continuity (1)
Related Publication 20230289433A1 · Sep 14, 2023
References Cited (25)
US 20100031325A1 · Maigne · 2010 [cited by examiner]
US 20190228145A1 · Shanbhogue · 2019 [cited by examiner]
US 20190311123A1 · Lal · 2019 [cited by examiner]
US 20200137031A1 · Pappachan · 2020 [cited by examiner]
US 20200145419A1 · Yitbarek · 2020 [cited by examiner]
US 20200310972A1 · Shanbhogue · 2020 [cited by examiner]
US 20210026543A1 · Trikalinou · 2021 [cited by examiner]
US 20210141658A1 · Sahita et al. · 2021 [cited by applicant]
“TEE Device Interface Security Protocol (TDISP)”, PCI-SIG Engineering Change Notice, 2020, 62 pages. [cited by applicant]
European Search Report and Search Opinion, EP App. No. 23152161.8, Jun. 22, 2023, 8 pages. [cited by applicant]
Office Action, EP App. No. 23152161.8, Nov. 26, 2024, 4 pages. [cited by applicant]
DMTF, “Security Protocol and Data Model (SPDM) Specification”, Version: 1.0.1, Mar. 19, 2021, 61 pages. [cited by applicant]
Intel Corporation, “Intel® Architecture Specification: Intel® Trust Domain Extensions (Intel® TDX) Module”, Jun. 2022, 316 pages. [cited by applicant]
Intel Corporation, “Intel® Device Attestation Model in Confidential Computing Environment”, Sep. 2022, 40 pages. [cited by applicant]
Intel Corporation, “Intel® Guest Hypervisor Communication Interface (GHCI) for Intel® Trust Domain Extensions (Intel® TDX) 1.0”, Dec. 2022, 39 pages. [cited by applicant]
Intel Corporation, “Intel® Guest Hypervisor Communication Interface (GHCI) for Intel® Trust Domain Extensions (Intel® TDX) 1.5”, Jul. 2022, 71 pages. [cited by applicant]
Intel Corporation, “Intel® Software Enabling for Intel® TDX in Support of TEE-I/O”, Revision 1.00, Sep. 2022, 26 pages. [cited by applicant]
Intel Corporation, “Intel® TDS Module Architecture Specification: TD Migration”, Sep. 2021, 68 pages. [cited by applicant]
Intel Corporation, “Intel® TDX Virtual Firmware Design Guide”, Dec. 2022, 68 pages. [cited by applicant]
Intel Corporation, “Intel® Trust Domain CPU Architectural Extensions”, May 2021, 40 pages. [cited by applicant]
Intel Corporation, “Intel® Trust Domain Extensions (Intel® TDX) Module Architecture Application Binary Interface (ABI) Reference Specification”, Sep. 2021, 296 pages. [cited by applicant]
Intel Corporation, “Intel® Trust Domain Extensions (Intel® TDX) Module Base Architecture Specification”, Sep. 2021, 133 pages. [cited by applicant]
Intel Corporation, “Intel® Trust Domain Extensions (TDX) Migration TD Design Guide”, Oct. 2021, 49 pages. [cited by applicant]
Intel Corporation, “Intel® Trust Domain Extensions—SEAM Loader (SEAMLDR) Interface Specification”, Mar. 2022, 26 pages. [cited by applicant]
Intel Corporation, “Intel® Trust Domain Extensions”, White Paper, Aug. 2022, 9 pages. [cited by applicant]