Configurable Memory Protection Circuit for Legacy Software Compatibility
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current encryption and data integrity protection mechanisms in computing systems are inefficient, particularly in scenarios where legacy software interacts with modern data validation systems, leading to false data integrity errors and vulnerabilities to memory corruption attacks.
Innovation Solution
The implementation of a configurable memory protection system that offers two modes: 'Generate, but not Validate' (GNV) and 'Generate and Validate' (GV), allowing selective application of encryption, decryption, and data validation services based on memory domain configurations, enabling both legacy and enlightened software to operate securely without data integrity errors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data validation mechanisms are implemented alongside encryption/decryption protection mechanisms, then data integrity is improved, but false data integrity errors occur when legacy software interacts with the system
Solution Approach 1:
The system dynamically switches between two operational modes: GNV mode (Generate but not Validate) for legacy software compatibility and GV mode (Generate and Validate) for enhanced security. This dynamic configuration allows the same hardware platform to serve both legacy and modern software requirements without compromise.
Solution Approach 2:
The invention changes the operational parameter of the data validation mechanism by introducing a configurable mode that toggles between validation enabled and disabled states. This parameter change resolves the contradiction by allowing legacy software to operate in GNV mode without triggering false errors while enlightened software operates in GV mode with full validation.
2Reliability
If full data validation and encryption protections are applied to all software, then security is improved, but legacy software experiences false data integrity errors
Solution Approach 1:
The system applies different quality levels of protection to different software types: GNV mode provides encryption without validation for legacy software, while GV mode provides both encryption and validation for enlightened software. This local differentiation resolves the contradiction by tailoring the security approach to each software category's capabilities.
Solution Approach 2:
The invention segments the software ecosystem into two categories (legacy and enlightened) and applies distinct protection mechanisms to each segment. This segmentation allows the system to maintain high security for modern software while ensuring compatibility with legacy software through appropriate mode selection.
3Reliability
If encryption and data validation services are always enabled, then protection against memory corruption attacks is improved, but system complexity and performance overhead increase
Solution Approach 1:
The hardware platform achieves multi-functionality by supporting both GNV and GV modes, allowing it to provide appropriate protection levels for different software types using the same underlying infrastructure. This universality reduces system complexity compared to requiring separate hardware platforms for different software types.
Data Source
AI summary
Techniques and mechanisms for configuring services which variously facilitate data protection. In an embodiment, circuitry coupled to a memory comprises both a first circuit which calculates integrity information based on data, and a second circuit which evaluates data validity based on such integrity information. A configuration of the circuitry provides a combination of one or more services which is specific to a corresponding domain of the memory. With respect to accesses to the corresponding domain, the configuration prevents an access to the first circuit while an access to the second circuit is permitted. In another embodiment, a processor signals the circuitry to transition to another configuration which, with respect to accesses to the corresponding domain, permits access to both the first circuit and the second circuit.


