Policies for secrets in trusted execution environments
Abstract
A computing device executes one or more trusted execution environment (TEE) processes in a TEE of a processor. The one or more TEE processes cryptographically protect a secret and a policy. The policy specifies a plurality of conditions on usage of the secret. A particular non-TEE process generates a request whose fulfillment involves an action requiring use of the secret. Responsive to the request, one or more non-TEE processes determine whether a first subset of the plurality of conditions is satisfied. Responsive to the first subset of the plurality of conditions being satisfied, the one or more TEE processes determine that a second, different subset of the plurality of conditions is satisfied. Responsive to determining the second subset of the plurality of conditions is satisfied, the one or more TEE processes use the secret to perform the action.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
cryptographically protecting, using one or more trusted execution environment processes executing inside a trusted execution environment of the one or more processors, a secret and a policy specifying a plurality of conditions on usage of the secret; generating, by the one or more processors, using one or more non-trusted execution environment processes executing outside the trusted execution environment of the one or more processors, a request to perform an action using the secret; responsive to generating the request, determining, by the one or more processors, using the one or more trusted execution environment processes, whether the plurality of conditions is satisfied by the request; and responsive to determining that the plurality of conditions is satisfied, performing, by the one or more processors, using the one or more trusted execution environment processes and the secret, the action.
2 . The method of claim 1 , wherein determining whether the plurality of conditions is satisfied comprises:
determining, by the one or more processors, using the one or more trusted execution environment processes, whether a first subset of the plurality of conditions is satisfied; responsive to determining that the first subset of the plurality of conditions is satisfied, determining, by the one or more micro-processors, using the one or more trusted execution environment processes, that a second, different subset of the plurality of conditions is satisfied by the request; and responsive to the second subset of the plurality of conditions being satisfied, determining that the plurality of conditions is satisfied.
3 . The method of claim 1 , wherein:
the request is a first request and the action is a first action, and the method further comprises: generating, by the one or more processors, using the one or more non-trusted execution environment processes, a second request to perform a second action using the secret; and responsive to generating the second request, determining, by the one or more processors, using the one or more trusted execution environment processes, whether the plurality of conditions is satisfied by the second request; and responsive to determining that the plurality of conditions is not satisfied, refraining from performing, by the one or more processors, the second action.
4 . The method of claim 3 , wherein determining whether the plurality of conditions is satisfied comprises:
determining, by the one or more processors, using the one or more trusted execution environment processes, whether a subset of the plurality of conditions is satisfied by the second request; responsive to determining that the subset of the plurality of conditions is not satisfied by the second request, refraining from performing, by the one or more processors, the second action.
5 . The method of claim 3 , wherein the subset of the plurality of conditions is a first subset and determining whether the plurality of conditions is satisfied comprises:
responsive to determining that the first subset of the plurality of conditions is satisfied by the second request, determining, by the one or more processors, using the one or more trusted execution environment processes, whether a second, different subset of the plurality of conditions is satisfied by the second request; and responsive to determining that the second subset of the plurality of conditions is not satisfied by the second request, refraining from performing, by the one or more processors, the second action.
6 . The method of claim 1 , wherein the plurality of conditions comprises one or more of:
a condition based on a time since a last unlock of a device comprising the one or more processors; a condition based on whether a display screen of the device is on; a condition based on whether the device is unlocked; a condition based on an idle time of the device; a condition setting a maximum rate of attempts to use the secret; a condition setting a maximum number of uses of the secret per boot of the device; a condition that only permits a bootloader of the device to use the secret; a condition based on a geographic location of the device; and a condition based on the device receiving an indication of biometric data of an authorized user.
7 . The method of claim 1 , wherein the request is a first request, the non-trusted execution environment processes include an application programming interface process, and the method further comprising:
receiving, by the one or more processors, using the application programming interface process, the first request; responsive to receiving the first request:
generating, by the one or more processors, using the application programming interface process, a second request; and
responsive to generating the second request, providing, by the one or more processors, using the one or more trusted execution environment processes, the policy to the application programming interface process for modification.
8 . The method of claim 1 , further comprising:
responsive to the plurality of conditions being satisfied, validating, by the one or more processors, using the one or more trusted execution environment processes, that no unauthorized modifications to the policy have occurred prior to performing the action.
9 . The method of claim 1 , wherein the secret comprises a cryptographic key.
10 . The method of claim 1 , wherein a hardware architecture of the one or more processors isolates processes executed by the one or more processors in the trusted execution environment of the one or more processors from processes operating in an operating system outside the trusted execution environment of the one or more processors.
11 . A computing device comprising:
one or more processors configured to provide a trusted execution environment that executes one or more trusted execution environment processes and a non-trusted execution environment that executes one or more non-trusted execution environment processes, wherein the one or more processors are further configured to:
cryptographically protect, using one or more trusted execution environment processes, a secret and a policy specifying a plurality of conditions on usage of the secret;
generate, using one or more non-trusted execution environment processes executing outside the trusted execution environment, a request to perform an action using the secret;
responsive to generating the request, determine, using the one or more trusted execution environment processes, whether the plurality of conditions is satisfied by the request; and
responsive to determining that the plurality of conditions is satisfied, perform, using the one or more trusted execution environment processes and the secret, the action.
12 . The computing device of claim 11 , wherein the request is a first request, the one or more non-trusted execution environment processes include an application programming interface process, and the one or more processors are further configured to:
receive, using the application programming interface process, the first request; responsive to receiving the first request:
generate, using the application programming interface process, a second request; and
responsive to generating the second request, provide, using the one or more trusted execution environment processes, the policy to the application programming interface process for modification.
13 . The computing device of claim 11 , wherein the one or more processors are further configured to:
responsive to the plurality of conditions being satisfied, validate, using the one or more trusted execution environment processes, that no unauthorized modifications to the policy have occurred prior to performing the action.
14 . The computing device of claim 11 , wherein the secret comprises a cryptographic key.
15 . The computing device of claim 11 , wherein a hardware architecture of the one or more processors isolates processes executed by the one or more processors in the trusted execution environment of the one or more processors from processes operating in an operating system outside the trusted execution environment of the one or more processors.
16 . A computer-readable storage medium comprising instructions that, when executed by one or more processors, cause the one or more processors to:
cryptographically protect, using one or more trusted execution environment processes executing inside a trusted execution environment of the one or more processors, a secret and a policy specifying a plurality of conditions on usage of the secret; generate, using one or more non-trusted execution environment processes executing outside the trusted execution environment, a request to perform an action using the secret; responsive to generating the request, determine, using the one or more trusted execution environment processes, whether the plurality of conditions is satisfied by the request; and responsive to determining that the plurality of conditions is satisfied, perform, using the one or more trusted execution environment processes and the secret, the action.
17 . The computer-readable storage medium of claim 16 , wherein the request is a first request, the one or more non-trusted execution environment processes include an application programming interface process, and the instructions, when executed, further cause the one or more processors to:
receive, using the application programming interface process, the first request; responsive to receiving the first request:
generate, using the application programming interface process, a second request; and
responsive to generating the second request, provide, using the one or more trusted execution environment processes, the policy to the application programming interface process for modification.
18 . The computer-readable storage medium of claim 16 , wherein the instructions, when executed, further cause the one or more processors to:
responsive to the plurality of conditions being satisfied, validate, using the one or more trusted execution environment processes, that no unauthorized modifications to the policy have occurred prior to performing the action.
19 . The computer-readable storage medium of claim 16 , wherein the secret comprises a cryptographic key.
20 . The computer-readable storage medium of claim 16 , wherein a hardware architecture of the one or more processors isolates processes executed by the one or more processors in the trusted execution environment of the one or more processors from processes operating in an operating system outside the trusted execution environment of the one or more processors.Join the waitlist — get patent alerts
Track US2018060609A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.