Flexible Access Control Configurations for Shared Memory Subsystems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current access control configurations for shared memory in communications systems increase device complexity and power usage due to reliance on a trusted security domain for dynamic reconfiguration, which can be unfeasible to find and implement effectively across multiple sub-systems.

Innovation Solution

Implementing a flexible access control configuration in hardware that allows individual sub-systems to manage access control, using additional configuration fields to specify exclusive write permissions and a chain of delegation, reducing the need for a trusted security domain and minimizing complexity and power usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a trusted security domain is used to manage access control for shared memory, then security is improved, but device complexity and power usage increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides access control management into segments: a trusted security domain handles high-level policy decisions, while individual sub-systems autonomously manage their own access control configurations for shared memory resources. This segmentation reduces the burden on the central security domain and distributes complexity to where it is needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Individual sub-systems are empowered to self-manage their access control configurations without requiring constant intervention from the trusted security domain. Each sub-system can independently configure and update access control rules for shared memory, reducing overall system complexity and power consumption while maintaining security through decentralized autonomy.

Inventive Principle:
Principle #25Self-service

2Reliability

If a trusted security domain is used to manage access control for shared memory, then security is improved, but power usage increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower usage
Core Design Contradiction:
ReliabilityVSUse of energy by stationary object

Solution Approach 1:

The patent segments access control management functions so that the power-intensive trusted security domain only performs occasional high-level policy updates, while routine access control operations are handled locally by individual sub-systems with minimal power consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Sub-systems autonomously manage their own access control configurations without requiring continuous power-intensive operations from the trusted security domain, significantly reducing overall system power usage while maintaining security through decentralized self-management.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If additional configuration fields are added to access control rules, then access control flexibility is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control flexibilityVSAvoidconfiguration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by adding configuration fields specifically where needed in the access control rules, rather than uniformly across all system components. Individual sub-systems can selectively utilize these fields based on their specific requirements, providing flexibility without imposing unnecessary complexity elsewhere in the system.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access control configuration is made dynamic and adaptable through additional fields that allow sub-systems to modify their access rules as needed. The configuration structure can evolve and adapt to different scenarios without requiring complete reconfiguration, balancing flexibility with manageable complexity through incremental adaptability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11928349B2Access control configurations for shared memory
Publication Date: 2024.03.12 QUALCOMM INC
  • US11928349B2 patent drawing
  • US11928349B2 patent drawing
  • US11928349B2 patent drawing

AI summary

Methods, systems, and devices for access control configurations for inter-processor communications are described to support reconfiguration of a dynamic access control configuration at a device. The configuration may support additional configuration fields that may be added to existing access control rules of the device. A processor of the device may request creation of a new shared memory resource, using a subregion of an existing memory resource, where the additional fields may indicate a parent memory resource for the new memory resource. The additional fields may also include a value which may indicate a processor which has write permission for a respective memory region of the shared memory, where other processors of the device may be prevented from writing to the memory region. The additional fields may further indicate a chain of delegation, or a history, of which processors have been assigned the exclusive write permission for the respective memory region.