Hardware Identity Impersonation for Real-Time Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing access control techniques in devices require complex interactions between software entities and hardware components to share access to target regions, leading to reduced device performance and failure to meet real-time performance goals.

Innovation Solution

Implementing a hardware identity impersonator component that allows access domains to impersonate each other's identities, reducing the need for reconfiguration of memory management and protection units by using a hardware identity impersonator to manage access requests and permissions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex software configuration procedures are used to manage access control, then access control functionality is achieved, but device performance deteriorates and real-time performance goals are not met

Engineering Contradiction:
Improveaccess control functionalityVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces complex software-based access control mechanisms with a hardware identity impersonator that operates at the hardware level. The hardware entity directly manages access permissions and identity impersonation without requiring software reconfiguration, thereby maintaining reliable access control while significantly improving device performance and meeting real-time performance requirements.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Adaptability or versatility

If hardware components are reconfigured to share access to target regions, then access sharing is enabled, but the complexity of interactions between software entities and hardware components increases

Engineering Contradiction:
Improveaccess sharing capabilityVSAvoidinteraction complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The hardware identity impersonator acts as an intermediary between access domains, enabling them to share access to target regions without direct reconfiguration of hardware components. The impersonator manages the complexity of access sharing by maintaining identity mappings and handling permission transitions internally, thereby reducing interaction complexity while preserving adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The hardware identity impersonator autonomously manages access sharing operations without requiring software entities to perform complex reconfiguration tasks. The impersonator self-manages identity impersonation, access permission validation, and target region access control, thereby reducing the complexity of interactions while maintaining full access sharing functionality.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If complex interactions are performed to share target access, then access sharing is achieved, but access setup time increases

Engineering Contradiction:
Improveaccess sharing functionalityVSAvoidaccess setup time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The hardware identity impersonator pre-establishes identity mappings and access permission structures before actual access operations occur. By preparing access control configurations in advance and maintaining them in hardware structures, the system enables rapid access sharing without time-consuming reconfiguration operations, thereby reducing access setup time while preserving full sharing functionality.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12432204B2Hardware identity impersonation for target access control
Publication Date: 2025.09.30 QUALCOMM INC
  • US12432204B2 patent drawing
  • US12432204B2 patent drawing
  • US12432204B2 patent drawing

AI summary

Systems and techniques are provided for identity impersonation in access control systems. For example, a process for identity impersonation in access control systems can include: receiving, at a hardware identity impersonator from a first access domain, a request to make a target region accessible to a second access domain; updating a second access domain identity data structure to include an entry corresponding to the first access domain, the entry comprising an address of the target region and a first access domain identifier; receiving, at the hardware identity impersonator from the second access domain, an access request to access the target region, wherein the access request comprises an address and a second access domain identifier of the second access domain; and transmitting, at the hardware identity impersonator based on the access request, the address and the first access domain identifier to a memory management unit (MMU) of an access control system.