Hardware Access Control Circuit for Per-User Memory Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current software-based per-user access control mechanisms for large-scale datasets are vulnerable to software bugs and security exploits, failing to provide robust protection against unauthorized access and data breaches.

Innovation Solution

Implementing a hardware-based fine-grained access control list (ACL) system that enforces per-user security controls through a security index linked to user data blocks, ensuring that each user's access is managed at a granular level, including data words or bytes, and utilizing a per-user authentication circuitry to validate memory access requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If software-based access control mechanisms are used to manage per-user access to large-scale datasets, then ease of operation and implementation are improved, but security reliability deteriorates due to vulnerability to software bugs and security exploits

Engineering Contradiction:
Improveease of implementationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based access control mechanisms with a hardware-based access control system. The hardware access control circuit is integrated into the memory device, providing security controls that are implemented in hardware rather than software, thereby eliminating vulnerabilities to software bugs and security exploits while maintaining ease of operation through automated hardware-enforced access decisions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces an intermediary hardware access control circuit that sits between the processing elements and the memory device. This intermediary component receives access requests, evaluates security policies, and controls memory access based on user credentials and data classification, providing a dedicated security layer that protects against unauthorized access without requiring complex software implementation

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If fine-grained per-user access control is implemented at the data word or byte level, then security precision is improved, but device complexity increases due to the need for hardware-based ACL systems

Engineering Contradiction:
Improveaccess control precisionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the memory device into multiple security zones or partitions, each with different security attributes and access control policies. This segmentation allows fine-grained control over different portions of the memory, enabling precise access control at the data word or byte level while managing complexity through organized structural divisions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security parameters of memory regions dynamically based on user credentials, data classification levels, and access policies. The hardware access control circuit evaluates multiple parameters (user identity, data sensitivity, access type) and adjusts access permissions accordingly, enabling fine-grained control without requiring complex manual configuration for each access scenario

Inventive Principle:
Principle #35Parameter changes

3Reliability

If hardware-based authentication circuitry is added to validate memory access requests, then security reliability is improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmanufacturing ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the access control functionality directly into the memory device structure, combining storage elements with security control logic in a single integrated component. This merging eliminates the need for separate hardware authentication modules, reducing manufacturing steps and simplifying production while maintaining high security reliability through hardware-enforced access control

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent designs the hardware access control circuit to perform multiple security functions including authentication, authorization, encryption key management, and access logging within a single integrated component. This multi-functionality reduces the number of separate hardware elements needed, simplifying manufacturing while providing comprehensive security protection

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If multiple users are allowed to access specific subsets of large datasets concurrently, then productivity is improved, but security management complexity increases

Engineering Contradiction:
Improvedata access efficiencyVSAvoidaccess control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements dynamic access control where security permissions are automatically adjusted based on real-time conditions such as user identity, data classification, access patterns, and current system state. The hardware access control circuit dynamically evaluates security policies and modifies access permissions without requiring manual intervention, enabling concurrent multi-user access while maintaining security through adaptive control

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4575872A1Apparatus and method for per-user secure access control with fine granularity
Publication Date: 2025.06.25 INTEL CORP
  • EP4575872A1 patent drawingFigure 1
  • EP4575872A1 patent drawingFigure 2
  • EP4575872A1 patent drawingFigure 3(A)

AI summary

An apparatus and method for per-user fine-grained data access security. For example, one embodiment of a processor comprises: a plurality of cores to execute instructions associated with a plurality of jobs to generate memory access requests on behalf of a plurality of users; memory access circuitry to couple at least one core of the plurality of cores to a memory, the memory access circuitry comprising: per-user authentication circuitry operable to perform an access check for a request to access a data block in the memory at a sub-page granularity, the request comprising a security index associated with the data block; the per-user authentication circuitry to use the security index to identify corresponding bits within an access control data structure to determine whether to provide access to the data block in response to the request.