Distributed Security Controller for SoC Subsystems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In large data processing systems, especially system-on-a-chip (SoC) systems, security components from various vendors lack a standard method for managing security states, and existing security controllers are isolated and cannot leverage their trustworthiness to enhance the security of the entire SoC platform, leading to potential security vulnerabilities and power management inefficiencies.
Innovation Solution
Implementing a data processing system with local security controllers for each subsystem, allowing immediate response to local state conditions, such as fault detection and tamper events, and enabling independent security policy enforcement, which notifies a central security controller while preventing compromised subsystems from affecting the rest of the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single security controller is used to manage all security components in the system, then centralized security management is achieved, but a security failure in one subsystem affects all security components system-wide
Solution Approach 1:
The patent divides the monolithic security controller into multiple independent regional security controllers, each responsible for a specific subsystem. This segmentation isolates security failures to individual regions, preventing system-wide propagation while maintaining centralized coordination through the master security controller.
Solution Approach 2:
The master security controller acts as an intermediary that coordinates between multiple regional security controllers and the rest of the system. It receives security state information from regional controllers and distributes security policies, enabling centralized management without direct coupling between subsystems.
2Loss of energy
If security components are powered off for power savings, then power consumption is reduced, but security response time increases when security events occur
Solution Approach 1:
Each regional security controller is designed to autonomously detect security events and execute security policies without requiring wake-up signals or external intervention. This self-service capability ensures immediate security response even when the controller is in a low-power state, as the controller can rapidly transition to active state upon detecting security-relevant events.
3Adaptability or versatility
If a centralized security state machine is used to manage all security components, then unified security policy enforcement is achieved, but lack of standard methods for third-party security components reduces adaptability
Solution Approach 1:
The regional security controllers are designed with universal interfaces and standardized security state machines that can work with security components from different vendors. This universality allows the system to accommodate third-party security components without requiring vendor-specific integration, while the standardized state management reduces overall system complexity.
Data Source
AI summary
A data processing system includes a plurality of subsystems, a plurality of local security controllers, and a central security controller. Each subsystem of the plurality of subsystems has a security component for providing a security function. A local security controller corresponds to each one of the subsystems. Each local security controller ensures compliance of the security component with local security policies of the subsystem to which the local security controller corresponds. The central security controller is coupled to the local security controller of each of the plurality of subsystems. The central security controller ensures data processing system compliance with system wide security policies. In the event of a detected security violation, the local security controller may respond automatically, without involvement of the central security controller. A method for securing the data processing system is also provided.


