Automated Hardware Security Logic Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current hardware security techniques for microprocessor systems rely on manual processes for implementing security aspects, which are cumbersome and inefficient, particularly in configuring information flow control, leading to suboptimal hardware design and increased complexity.

Innovation Solution

A method that involves receiving a hardware design with annotated labels and security properties, automatically assigning security levels, and generating optimized hardware security logic using high-level programming languages like Tortuga Logic's Sentinel, enabling automated implementation of secure information flow control and reducing manual configuration efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual processes are used for implementing hardware security design, then security aspects can be implemented, but the process becomes cumbersome and inefficient

Engineering Contradiction:
Improvehardware securityVSAvoiddesign efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system automatically analyzes hardware design code, identifies security vulnerabilities, and generates security configurations without requiring manual security expert intervention. The automated analysis engine scans the hardware description language code, detects potential security issues, and produces configuration files that enforce security policies, enabling the design process to service itself regarding security concerns.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical processes of security analysis and configuration with an automated computational system. The mechanical act of manually reviewing and configuring security aspects is substituted by an electronic automated analysis engine that processes hardware design code and generates security configurations algorithmically, significantly improving productivity while maintaining or enhancing security reliability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If manual configuration of information flow control is implemented, then security policies can be enforced, but device complexity increases

Engineering Contradiction:
Improveinformation flow controlVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system automatically analyzes the hardware design code to identify information flow paths and generates appropriate security configurations without manual intervention. The automated engine scans the hardware description language, traces data flows between components, and produces configuration files that enforce information flow control policies, eliminating the need for complex manual configuration while maintaining security enforcement.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs security analysis and configuration generation during the design phase, before the hardware is manufactured or deployed. By analyzing the hardware description language code upfront and generating security configurations in advance, the system eliminates the need for complex post-manufacturing configuration, reducing overall device complexity while ensuring information flow control is built-in from the start.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If automated analysis of hardware design code is performed, then security configurations can be generated automatically, but analysis time and computational resources increase

Engineering Contradiction:
Improveconfiguration generationVSAvoidanalysis time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system performs security analysis during the hardware design phase, while the design is still represented as hardware description language code. By conducting the analysis at this early stage, the system leverages the structured and readable nature of the design code, enabling efficient automated analysis that generates security configurations quickly without requiring time-consuming post-manufacturing inspection or testing.

Inventive Principle:
Principle #10Preliminary action

4Productivity

If security configurations are generated automatically, then manual effort is reduced, but precision in identifying security requirements may decrease

Engineering Contradiction:
Improveconfiguration generation speedVSAvoidsecurity requirement identification
Core Design Contradiction:
ProductivityVSManufacturing precision

Solution Approach 1:

The system incorporates feedback mechanisms where the automated analysis engine continuously refines its security configuration generation based on the hardware design code structure and identified security patterns. The system analyzes the code, generates initial configurations, and iteratively improves the configurations by feedback from the code analysis results, ensuring both automation efficiency and precision in identifying security requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10289873B2Generating hardware security logic
Publication Date: 2019.05.14 ARTERIS INC
  • US10289873B2 patent drawing
  • US10289873B2 patent drawing
  • US10289873B2 patent drawing

AI summary

The present disclosure includes systems and techniques relating to information flow and hardware security for digital devices and microprocessor systems. In general, in one implementation, a technique includes: receiving a hardware design specifying an implementation for information flow in a hardware configuration; receiving one or more labels annotating the hardware design; receiving a security property specifying a restriction relating to the one or more labels for implementing a secure information flow in the hardware configuration; designating each of the one or more labels to a corresponding security level in accordance with the specified restriction; and automatically assigning a respective value to each of the one or more labels in the hardware design, wherein each respective value is determined in accordance with the corresponding security level designated for each of the one or more labels.