Bus Privilege Level Encoding for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional systems for controlling access to resources in electronic devices are complex and costly, and often fail to adequately protect against unauthorized access due to their complexity.
Innovation Solution
Incorporating a privilege information portion into the bus that interconnects requester and target devices, which carries information indicating the privilege level of the program module initiating a request, allowing the target device to decide on access permissions based on predefined privilege levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional access control mechanisms are used, then security protection is provided, but system complexity and cost increase
Solution Approach 1:
The patent combines the access control functionality directly into the bus interface of the target device, merging the previously separate access control mechanism with the existing bus structure. This integration eliminates the need for additional complex access control hardware or software layers, thereby maintaining security while reducing system complexity and cost.
Solution Approach 2:
The bus interface is designed to handle multiple functions including data transfer, control signals, and access control permissions. By making the bus interface universal and multi-functional, the patent eliminates the need for separate dedicated access control mechanisms, thereby reducing system complexity while maintaining security protection.
2Reliability
If traditional access control mechanisms are used, then security protection is provided, but cost increases
Solution Approach 1:
The access control functionality is merged into the existing bus interface circuitry of the target device. By reusing existing hardware components and integrating access control logic into the bus interface, the patent avoids the need for additional expensive access control hardware, thereby maintaining security protection while reducing system cost.
Solution Approach 2:
The target device's bus interface autonomously handles access control decisions based on permission bits associated with memory locations. This self-service approach eliminates the need for external access control hardware or complex software validation, thereby reducing system cost while maintaining security.
3Reliability
If detailed access control validation is performed, then unauthorized access is prevented, but processing time increases
Solution Approach 1:
Access control permissions are pre-configured in the target device's bus interface through permission bits associated with each memory location. By performing the access control validation setup in advance, the patent enables rapid runtime access decisions without requiring complex real-time validation, thereby preventing unauthorized access while minimizing processing time loss.
Solution Approach 2:
The patent divides the bus interface into multiple independent decoders, each handling specific memory locations or ranges with their own permission bits. This segmentation allows parallel access control validation for different memory locations, thereby preventing unauthorized access while reducing overall processing time through concurrent validation.
Data Source
AI summary
A bus between a requester and a target component includes a portion dedicated to carry information indicating a privilege level, from among a plurality of privilege levels, of machine-readable instructions executed on the requester.


