Computing Unit Access Manager for Secure Multi-Core Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computing systems are vulnerable to attacks, particularly at the hardware level, as existing security measures are limited in detecting and preventing hardware-based intrusions, and traditional capability-based security systems lack authenticity verification, creating single points of failure and management complexities in multi-core processing environments.

Innovation Solution

A computing device with a network-on-a-chip architecture, featuring a computing unit access manager that requires a majority vote for response validation, utilizing authentication tokens and a reconfiguration voter to ensure secure access and fault tolerance across multiple computing units, allowing independent chains and dynamic quorum adjustment for resilience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional capability-based security is used in multi-core systems, then access control can be implemented, but authenticity verification is impossible and single points of failure are created

Engineering Contradiction:
Improvesystem securityVSAvoidcapability chain management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the capability verification process into individual voting units, where each computing unit independently verifies capabilities and contributes to a collective decision. This eliminates the single point of failure in traditional chains by distributing trust across multiple independent verification points.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple independent capability verification results are merged through a voting mechanism to produce a single authoritative decision. The voting unit combines inputs from multiple computing units, allowing the system to tolerate individual failures while maintaining overall security and authenticity verification.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If majority vote mechanism is implemented for response validation, then security and fault tolerance are enhanced, but system complexity and overhead increase

Engineering Contradiction:
Improvefault toleranceVSAvoidvoting mechanism overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The voting mechanism is integrated into the access control flow itself, so that voting occurs as a natural part of the request-response cycle rather than as a separate post-processing step. This reduces overhead by performing security verification in parallel with normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The voting unit serves multiple functions simultaneously: it verifies authenticity, detects hardware intrusions, provides fault tolerance, and enables dynamic quorum adjustment. This multi-functionality reduces the need for separate dedicated mechanisms for each security concern.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If dynamic quorum adjustment is allowed, then system adaptability and resilience improve, but control and management complexity increase

Engineering Contradiction:
Improvequorum flexibilityVSAvoidquorum management
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The quorum requirement is made dynamic rather than fixed, allowing the voting unit to adjust the number of required agreeing responses based on system conditions, threat levels, and operational context. This enables the system to adapt its security posture without manual reconfiguration.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The voting mechanism automatically manages quorum adjustment based on predefined policies and system state, eliminating the need for manual intervention. The system self-regulates its security parameters in response to detected conditions such as suspected intrusions or failures.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11416617B2Computing apparatus
Publication Date: 2022.08.16 UNIV DU LUXEMBOURG
  • US11416617B2 patent drawing
  • US11416617B2 patent drawing
  • US11416617B2 patent drawing

AI summary

There is disclosed a computing/data processing device comprising: a plurality of computing units, each computing unit comprising a computing resource; the computing device comprising at least three computing units, each computing unit comprising a/the same computing resource; each computing unit further comprising a computing unit access manager, each unit access manager being adapted to control access to the computing resource of the respective computing unit in response to at least one request; wherein, the computing unit access manager only allows a response to the at least one request if a majority of the computing units provide a same response to the at least one request; and wherein, the computing device comprising a network-on-a-chip, is provided on a chip and/or comprises an integrated chip (IC) or microprocessor. The IC beneficially comprises a Field-Programmable Gate Array (FPGA) device. In a preferred embodiment, the unit access manager controls access to the computing resource based on a token; the token comprising: a pointer to the respective computing resource, a set of rights relating to that computing resource, and a numerical representation of that computing resource.