Domain Register for Non-Hierarchical Security in Processors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer systems rely on hierarchical protection rings for security, which can be inflexible and lack fine-grained control, as they enforce trust based on a static hierarchy, limiting the ability to customize security operations across different domains without relying on a predefined hierarchy of trust.

Innovation Solution

Implementing a domain register in a computer processor to classify instructions into non-hierarchical domains, allowing for dynamic security operations by using permission bits from page table entries to control memory access and sandboxing, independent of the domain hierarchy, thereby enabling flexible and granular security configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hierarchical protection rings are used for security control, then system stability is maintained through predefined trust hierarchy, but security flexibility and fine-grained control are lost

Engineering Contradiction:
Improvesystem stabilityVSAvoidsecurity flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the monolithic protection ring hierarchy into multiple independent execution domains (e.g., domain 0 for hypervisor, domain 1 for operating system, domain 2 for applications). Each domain has its own permission set that can be independently configured, allowing fine-grained security control without requiring a rigid hierarchical structure. This segmentation enables simultaneous maintenance of system stability through clear domain boundaries and improvement of security flexibility through customizable domain-specific permissions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic domain switching capability where the processor can switch between different execution domains based on the instruction being executed. The domain register is dynamically updated to reflect the current execution context, and permission bits are dynamically selected based on the active domain. This dynamic behavior allows the system to adapt security configurations in real-time while maintaining overall system stability through controlled transitions between domains.

Inventive Principle:
Principle #15Dynamics

2Device complexity

If static hierarchy of trust is enforced, then security operations are simplified, but fine-grained control over resource access is limited

Engineering Contradiction:
Improvesecurity operation complexityVSAvoidfine-grained control precision
Core Design Contradiction:
Device complexityVSManufacturing precision

Solution Approach 1:

The patent applies local quality by assigning domain-specific permission sets that are tailored to the specific security requirements of each execution domain. Instead of applying uniform security rules across all code, the system configures different permission bits for different domains (e.g., hypervisor domain gets full access, application domain gets restricted access). This allows precise fine-grained control over resource access while keeping security operations manageable through domain-based organization.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the security control parameter from a static hierarchical level to a dynamic domain identifier. The domain register holds a domain identifier that changes based on the execution context, and this parameter change triggers the selection of appropriate permission bits from the page table entry. This parameter change mechanism enables fine-grained control by allowing different permission configurations for different execution contexts while maintaining simplified security operations through a unified domain-based interface.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If domain-specific security settings are implemented, then resource access control is improved, but processor complexity increases

Engineering Contradiction:
Improveresource access controlVSAvoidprocessor complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent achieves universality by using a single domain register and a single page table entry structure to handle security control for all execution domains. The domain register serves multiple functions: it identifies the current execution domain, selects the appropriate permission set, and enables domain switching. The page table entry structure is designed to be universal, containing permission bits that apply to all domains through the domain identifier. This universal approach improves resource access control while minimizing processor complexity by avoiding the need for separate security mechanisms for each domain.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces the domain register as an intermediary between the execution context and the security control mechanism. Instead of directly hardcoding security rules into the processor for each domain, the domain register acts as a mediator that translates the execution context into the appropriate security permissions. This intermediary approach improves resource access control by enabling flexible domain-specific permissions while reducing processor complexity by centralizing the security translation logic in a single register and page table structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11620239B2Domain register for instructions being executed in computer processors
Publication Date: 2023.04.04 MICRON TECHNOLOGY INC
  • US11620239B2 patent drawing
  • US11620239B2 patent drawing
  • US11620239B2 patent drawing

AI summary

Systems, apparatuses, and methods related to a domain register of a processor in a computer system are described. The computer system has a memory configured to at least store instructions of routines that are classified in multiple predefined, non-hierarchical domains. The processor stores in the domain register an identifier of a current domain of a routine that is being executed in the processor. The processor is configured to perform security operations based on the content of the domain register and the security settings specified respectively for the predefined, non-hierarchical domains.