Configurable Memory Protection Circuit for Legacy Software Compatibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current encryption and data integrity protection mechanisms in computing systems are inefficient, particularly in scenarios where legacy software interacts with modern data validation systems, leading to false data integrity errors and vulnerabilities to memory corruption attacks.

Innovation Solution

The implementation of a configurable memory protection system that offers two modes: 'Generate, but not Validate' (GNV) and 'Generate and Validate' (GV), allowing selective application of encryption, decryption, and data validation services based on memory domain configurations, enabling both legacy and enlightened software to operate securely without data integrity errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data validation mechanisms are implemented alongside encryption/decryption protection mechanisms, then data integrity is improved, but false data integrity errors occur when legacy software interacts with the system

Engineering Contradiction:
Improvedata integrityVSAvoidlegacy software compatibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically switches between two operational modes: GNV mode (Generate but not Validate) for legacy software compatibility and GV mode (Generate and Validate) for enhanced security. This dynamic configuration allows the same hardware platform to serve both legacy and modern software requirements without compromise.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the operational parameter of the data validation mechanism by introducing a configurable mode that toggles between validation enabled and disabled states. This parameter change resolves the contradiction by allowing legacy software to operate in GNV mode without triggering false errors while enlightened software operates in GV mode with full validation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If full data validation and encryption protections are applied to all software, then security is improved, but legacy software experiences false data integrity errors

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies different quality levels of protection to different software types: GNV mode provides encryption without validation for legacy software, while GV mode provides both encryption and validation for enlightened software. This local differentiation resolves the contradiction by tailoring the security approach to each software category's capabilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The invention segments the software ecosystem into two categories (legacy and enlightened) and applies distinct protection mechanisms to each segment. This segmentation allows the system to maintain high security for modern software while ensuring compatibility with legacy software through appropriate mode selection.

Inventive Principle:
Principle #1Segmentation

3Reliability

If encryption and data validation services are always enabled, then protection against memory corruption attacks is improved, but system complexity and performance overhead increase

Engineering Contradiction:
Improveprotection against memory corruption attacksVSAvoidconfiguration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware platform achieves multi-functionality by supporting both GNV and GV modes, allowing it to provide appropriate protection levels for different software types using the same underlying infrastructure. This universality reduces system complexity compared to requiring separate hardware platforms for different software types.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10795829B2Device, method and system to selectively provide data validation functionality
Publication Date: 2020.10.06 INTEL CORP
  • US10795829B2 patent drawing
  • US10795829B2 patent drawing
  • US10795829B2 patent drawing

AI summary

Techniques and mechanisms for configuring services which variously facilitate data protection. In an embodiment, circuitry coupled to a memory comprises both a first circuit which calculates integrity information based on data, and a second circuit which evaluates data validity based on such integrity information. A configuration of the circuitry provides a combination of one or more services which is specific to a corresponding domain of the memory. With respect to accesses to the corresponding domain, the configuration prevents an access to the first circuit while an access to the second circuit is permitted. In another embodiment, a processor signals the circuitry to transition to another configuration which, with respect to accesses to the corresponding domain, permits access to both the first circuit and the second circuit.