Multiprocessor Fabric Secure Boot Path Disabling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems face challenges in securing multiprocessor fabrics, particularly in disabling communication paths to ensure secure processing and prevent unauthorized access, as existing methods lack robustness in isolating portions of the system during operation.

Innovation Solution

A multiprocessor fabric configuration is received during the boot process, specifying the disabling of communication paths between processors and communication elements, which is automatically implemented in hardware, ensuring that these paths are not restorable via software, thereby isolating portions of the system for secure operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If communication paths in multiprocessor fabric are dynamically configurable to enable flexible operation, then system versatility is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvedynamic configurability of communication pathsVSAvoidunauthorized access to communication paths
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The multiprocessor fabric is segmented into secure and non-secure portions through configurable communication paths. The routing engine divides the fabric into distinct regions, allowing secure portions to be isolated from non-secure portions while maintaining overall system functionality. This segmentation enables selective access control without compromising system versatility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The communication paths are made dynamically configurable through routing engine control, allowing the system to switch between secure and non-secure modes as needed. The configurable paths enable the system to adapt its topology dynamically, creating secure isolation when required while maintaining full connectivity when security is not a concern.

Inventive Principle:
Principle #15Dynamics

2Object-affected harmful factors

If communication paths are disabled to ensure security, then system security is improved, but system functionality deteriorates

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidsystem operation capability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

Instead of disabling all communication paths, the fabric is segmented into secure and non-secure portions. Only the necessary paths are disabled or restricted to maintain security, while other paths remain active to preserve system functionality. This selective segmentation maintains productivity by keeping essential communication channels open.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security restrictions are applied locally to specific communication paths and portions of the fabric rather than globally. The routing engine configures secure paths with restricted access while leaving non-secure paths fully functional. This local application of security measures preserves overall system productivity while protecting critical areas.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If configurable communication paths are used to isolate system portions, then security is improved, but device complexity increases

Engineering Contradiction:
Improveisolation of secure portionsVSAvoidconfiguration and control of communication paths
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The routing engine serves multiple functions: it routes data packets, configures communication paths, enforces security policies, and manages fabric topology. This multi-functionality reduces the need for separate dedicated security management hardware, thereby managing complexity while providing comprehensive security and isolation capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10685143B2Secure boot sequence for selectively disabling configurable communication paths of a multiprocessor fabric
Publication Date: 2020.06.16 HYPERX HOLDINGS LLC
  • US10685143B2 patent drawing
  • US10685143B2 patent drawing
  • US10685143B2 patent drawing

AI summary

Disabling communication in a multiprocessor fabric. The multiprocessor fabric may include a plurality of processors and a plurality of communication elements and each of the plurality of communication elements may include a memory. A configuration may be received for the multiprocessor fabric, which specifies disabling of communication paths between one or more of: one or more processors and one or more communication elements; one or more processors and one or more other processors; or one or more communication elements and one or more other communication elements. Accordingly, the multiprocessor fabric may be automatically configured in hardware to disable the communication paths specified by the configuration. The multiprocessor fabric may be operated to execute a software application according to the configuration.