Centralized Access Control Library for Secure Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches to managing secure data in computing devices are cumbersome and vulnerable to unauthorized access, requiring individual trusted applications to be configured for credentials and access control, which can lead to inefficiencies and security risks.

Innovation Solution

A centralized access control system is implemented using an access control library, access control driver, and secure access manager within the operating system, which standardizes access requests and enforces rules, eliminating the need for individual trusted applications to manage credentials and reducing vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If individual trusted applications are configured for credentials and access control, then access control functionality is provided, but device complexity and vulnerability increase

Engineering Contradiction:
Improveaccess control functionalityVSAvoidconfiguration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent merges access control functionality into the operating system kernel, combining credential storage, access control policies, and authentication mechanisms into a unified centralized system. This eliminates the need for individual trusted applications to independently configure credentials and access control, thereby reducing device complexity while maintaining access control functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The operating system implements a universal access control framework that serves multiple trusted applications simultaneously. The centralized credential store and policy enforcement mechanism provide multi-functional access control across different applications and data types, reducing the need for application-specific configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If individual trusted applications manage their own credentials, then application autonomy is maintained, but security vulnerabilities increase

Engineering Contradiction:
Improveapplication autonomyVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces an intermediary access control manager within the operating system that mediates between trusted applications and secure data. This intermediary centralizes credential management and access control enforcement, reducing security vulnerabilities while maintaining application autonomy through standardized API interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments access control into distinct layers: credential storage in a protected operating system component, policy enforcement through centralized access control rules, and application-level requests through standardized interfaces. This segmentation isolates security-critical functions from individual applications, reducing vulnerability while preserving application functionality.

Inventive Principle:
Principle #1Segmentation

3Reliability

If centralized access control is implemented, then security is enhanced and vulnerabilities reduced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts access control functionality from individual trusted applications and places it in the operating system kernel. This extraction centralizes security management, enhancing security and reducing vulnerabilities while presenting a simplified interface to applications that do not need to understand the underlying complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The operating system's centralized access control system automatically manages credentials, enforces policies, and makes access decisions without requiring individual applications to implement their own access control logic. This self-service approach enhances security while reducing the apparent complexity for application developers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3586234B1Methods and apparatus for controlling access to secure computing resources
Publication Date: 2023.06.21 HUAWEI TECH CO LTD
  • EP3586234B1 patent drawingFigure 1
  • EP3586234B1 patent drawingFigure 2
  • EP3586234B1 patent drawingFigure 3

AI summary

A computing device has first and second operating systems with access to first and second memories, respectively. The second memory is provided for secure computing resources and is not accessible by applications in the first operating system. A software module executable within the first operating system receives requests for secure computing resources, adds access credentials and passes the requests to a software module in the second operating system.