Channel Filter Hardware Access Control for I/O Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device access control solutions are device-specific and lack scalability, relying on software which can be vulnerable to malware threats, especially in complex system software with large code bases, making it difficult to ensure secure access to sensitive data from various I/O devices.
Innovation Solution
A hardware-based trusted input/output path with a channel filter that enforces access control policies using unique device identifiers and secure enclaves, ensuring only authorized software can access I/O devices, with policies configurable by IT personnel and enforced through a secure element during the boot process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If device-specific access control mechanisms are used, then access security is improved for individual devices, but scalability across different devices deteriorates
Solution Approach 1:
The patent implements a universal access control mechanism through the channel filter that can manage multiple I/O devices across different platforms using a single hardware component. The filter uses configurable filter entries with device identifiers and access control policies that can be dynamically programmed, allowing the same hardware to secure diverse devices without requiring device-specific dedicated mechanisms.
2Ease of operation
If software-based access control is used, then ease of configuration is improved, but security against malware deteriorates
Solution Approach 1:
The patent introduces a hardware intermediary component (the channel filter) that sits between the I/O devices and the software applications. This hardware filter enforces access control policies independently of software, creating a security boundary that prevents malware in software from bypassing access controls. The filter mediates all data traffic through hardware-based verification of access rights.
Solution Approach 2:
The patent replaces software-based access control mechanisms with a hardware-based implementation. Instead of relying on software to enforce access policies (which can be compromised by malware), the system uses hardware circuits in the channel filter to physically enforce access control decisions, substituting the mechanical/software layer with a more secure hardware layer.
3Object-affected harmful factors
If hardware-based access control is used, then security against malware is improved, but device complexity increases
Solution Approach 1:
The patent segments the access control functionality into discrete filter entries within the channel filter, where each entry corresponds to a specific device or access policy. This segmentation allows the complex access control logic to be broken down into manageable units that can be independently configured and enforced, reducing the overall system complexity while maintaining strong security.
Data Source
AI summary
In one embodiment, an apparatus includes a channel filter and a security processor. The security processor is to: receive a plurality of device access control policies from a protected non-volatile storage of a platform; determine whether the plurality of device access control policies are verified; program the channel filter with a plurality of filter entries each associated with one of the plurality of device access control policies based on the determination; and remove a security attribute of the security processor from a policy register of the channel filter, to lock the channel filter for a boot cycle of the platform. Other embodiments are described and claimed.


