Capability Enforcement Processor Interposed Between CPU and Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Implementing capability-based data access protection in computing systems is challenging due to the difficulty of architectural changes and the overhead of operating system-based approaches, which can hinder efficient memory operation processing.

Innovation Solution

A capability enforcement processor is interposed between the system processor and memory to intercept and enforce memory requests based on capabilities maintained in a per-process capability space, providing data security without relying on CPU architectural changes or incurring operating system overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If capability-based access protection is implemented through CPU architectural changes, then data security is improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoidCPU architectural complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a capability enforcement processor as an intermediary component between the system processor and memory. This separate enforcement processor handles capability validation and memory access control, allowing the main CPU to remain simple while data security is enforced through the intermediary component that checks capabilities against memory access requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If capability-based access protection is implemented through operating system approaches, then data security is improved, but processing overhead increases

Engineering Contradiction:
Improvedata securityVSAvoidmemory operation processing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the software-based operating system capability management with a hardware-based capability enforcement processor. This hardware enforcement mechanism validates capabilities through dedicated circuitry and logic, significantly reducing processing overhead compared to software-based approaches while maintaining strong data security enforcement for memory operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If capability functionality is added to systems without native CPU support, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improvecapability support capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the capability management functionality into a separate capability enforcement processor that can be independently implemented and configured. This segmentation allows legacy systems without native CPU capability support to gain capability-based access control through an add-on component, avoiding the need to redesign the entire CPU architecture while maintaining system compatibility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10884953B2Capability enforcement processors
Publication Date: 2021.01.05 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10884953B2 patent drawing
  • US10884953B2 patent drawing
  • US10884953B2 patent drawing

AI summary

Example implementations relate to a capability enforcement processor. In an example, a capability enforcement processor may be interposed between a memory that stores data accessible via capabilities and a system processor that executes processes. The capability enforcement processor intercepts a memory request from the system processor and enforces the memory request based on capability enforcement processor capabilities maintained in per-process capability spaces of the capability enforcement processor.