Hardware-Controlled Access Lists for Granular Encrypted Data Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware assisted compute and memory security frameworks do not provide end-users with granular control over how data is shared, leaving data vulnerable to unauthorized access during transmission or storage.

Innovation Solution

A hardware system computer is implemented as a separate compute domain within a compute device, providing an in-band or out-of-band interface to allow entities to register and create secure channels for data access, enabling granular control over access to encrypted data through a hardware-controlled access control list.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware assisted compute and memory security frameworks are implemented, then data security is improved, but granular control over data sharing is lost

Engineering Contradiction:
Improvedata securityVSAvoidgranular control over data sharing
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the compute device into separate compute domains: a hardware system computer with vendor-exclusive access and user-accessible compute domains. This segmentation allows different security levels and access controls for different data, enabling granular control while maintaining overall security through hardware isolation boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning different access control properties to different data regions and compute domains. The hardware system computer has exclusive access to certain encrypted data regions, while other compute domains have controlled access through hardware-enforced access control lists, allowing security policies to be applied locally to specific data rather than uniformly across all data.

Inventive Principle:
Principle #3Local quality

2Reliability

If data is encrypted and stored in shared memory, then data privacy is improved, but access control complexity increases

Engineering Contradiction:
Improvedata privacyVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware system computer performs self-service by autonomously managing its own access to encrypted data without requiring software intervention. The hardware-enforced access control lists and encryption key management are handled automatically by the hardware system computer, reducing the complexity burden on software systems while maintaining strong access control.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces hardware-enforced access control lists as an intermediary layer between encrypted data and compute domains. This hardware-mediated access control mechanism simplifies the overall system by providing a single, hardware-enforced interface for access control rather than requiring complex software-based permission systems, while still enabling fine-grained access control policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If vendor-exclusive programmable circuit is added, then secure data sharing control is improved, but device complexity increases

Engineering Contradiction:
Improvesecure data sharing controlVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent merges the hardware system computer with the existing compute device architecture, integrating vendor-exclusive programmable circuitry into the fabric of the device. This merging allows secure data sharing control to be implemented without adding entirely separate hardware systems, reducing overall complexity while maintaining enhanced control capabilities through unified hardware management.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250260695A1Methods, apparatus, and articles of manufacture to securely share data
Publication Date: 2025.08.14 OPENCHIP & SOFTWARE TECHNOLOGIES SL
  • US20250260695A1 patent drawing
  • US20250260695A1 patent drawing
  • US20250260695A1 patent drawing

AI summary

Systems, apparatus, articles of manufacture, and methods are disclosed to securely share data. An example apparatus includes at least one first programmable circuit to obtain an access control list for an encrypted data object via a first communication channel with a data provider, the encrypted data object to be provided by the data provider via a second communication channel. Additionally, the example apparatus includes memory controller circuitry to permit or deny a request from at least one second programmable circuit to access the encrypted data object based on the access control list for the encrypted data object.