Flexible Access Control Configurations for Shared Memory Subsystems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current access control configurations for shared memory in communications systems increase device complexity and power usage due to reliance on a trusted security domain for dynamic reconfiguration, which can be unfeasible to find and implement effectively across multiple sub-systems.
Innovation Solution
Implementing a flexible access control configuration in hardware that allows individual sub-systems to manage access control, using additional configuration fields to specify exclusive write permissions and a chain of delegation, reducing the need for a trusted security domain and minimizing complexity and power usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a trusted security domain is used to manage access control for shared memory, then security is improved, but device complexity and power usage increase
Solution Approach 1:
The patent divides access control management into segments: a trusted security domain handles high-level policy decisions, while individual sub-systems autonomously manage their own access control configurations for shared memory resources. This segmentation reduces the burden on the central security domain and distributes complexity to where it is needed.
Solution Approach 2:
Individual sub-systems are empowered to self-manage their access control configurations without requiring constant intervention from the trusted security domain. Each sub-system can independently configure and update access control rules for shared memory, reducing overall system complexity and power consumption while maintaining security through decentralized autonomy.
2Reliability
If a trusted security domain is used to manage access control for shared memory, then security is improved, but power usage increases
Solution Approach 1:
The patent segments access control management functions so that the power-intensive trusted security domain only performs occasional high-level policy updates, while routine access control operations are handled locally by individual sub-systems with minimal power consumption.
Solution Approach 2:
Sub-systems autonomously manage their own access control configurations without requiring continuous power-intensive operations from the trusted security domain, significantly reducing overall system power usage while maintaining security through decentralized self-management.
3Adaptability or versatility
If additional configuration fields are added to access control rules, then access control flexibility is improved, but device complexity increases
Solution Approach 1:
The patent applies local quality by adding configuration fields specifically where needed in the access control rules, rather than uniformly across all system components. Individual sub-systems can selectively utilize these fields based on their specific requirements, providing flexibility without imposing unnecessary complexity elsewhere in the system.
Solution Approach 2:
The access control configuration is made dynamic and adaptable through additional fields that allow sub-systems to modify their access rules as needed. The configuration structure can evolve and adapt to different scenarios without requiring complete reconfiguration, balancing flexibility with manageable complexity through incremental adaptability.
Data Source
AI summary
Methods, systems, and devices for access control configurations for inter-processor communications are described to support reconfiguration of a dynamic access control configuration at a device. The configuration may support additional configuration fields that may be added to existing access control rules of the device. A processor of the device may request creation of a new shared memory resource, using a subregion of an existing memory resource, where the additional fields may indicate a parent memory resource for the new memory resource. The additional fields may also include a value which may indicate a processor which has write permission for a respective memory region of the shared memory, where other processors of the device may be prevented from writing to the memory region. The additional fields may further indicate a chain of delegation, or a history, of which processors have been assigned the exclusive write permission for the respective memory region.


