Invention Grant
- Patent Title: Deploying enclaves on different tee backends using a universal enclave binary
-
Application No.: US17960738Application Date: 2022-10-05
-
Publication No.: US12147530B2Publication Date: 2024-11-19
- Inventor: Ye Li , Anoop Jaishankar , John Manferdelli , David Ott , Andrei Warkentin
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Agency: King Intellectual Asset Management
- Main IPC: G06F21/53
- IPC: G06F21/53 ; G06F21/12 ; G06F21/54

Abstract:
The disclosure herein describes deploying a Virtual Secure Enclave (VSE) using a universal enclave binary and a Trusted Runtime (TR). A universal enclave binary is generated that includes a set of binaries of Instruction Set Architectures (ISAs) associated with Trusted Execution Environment (TEE) hardware backends. A TEE hardware backend is identified in association with a VSE-compatible device. A VSE that is compatible with the identified TEE hardware backend is generated on the VSE-compatible device and an ISA binary that matches the TEE hardware backend is selected from the universal enclave binary. The selected binary is linked to a runtime library of the TR and loads the linked binary into memory of the generated VSE. The execution of a trusted application is initiated in the generated VSE using a set of interfaces of the TR. The trusted application depends on the TR interfaces rather than the selected ISA binary.
Public/Granted literature
- US20240119138A1 DEPLOYING ENCLAVES ON DIFFERENT TEE BACKENDS USING A UNIVERSAL ENCLAVE BINARY Public/Granted day:2024-04-11
Information query