Hardware Policy Decision Point for Secure Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing software-only solutions for secure computing environments face performance limitations and security vulnerabilities, particularly in managing access to resources on Internet-connected devices operating in diverse contexts.
Innovation Solution
Implementing policy decision point (PDP) servers partially or fully in hardware using hardware description languages (HDL) such as Verilog or VHDL, incorporating logic gates, content addressable RAM, or other digital logic components to enhance performance, security, and flexibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software-only solutions are used for policy-based access control, then flexibility and ease of implementation are improved, but performance and security are worsened
Solution Approach 1:
The system segments the access control functionality into two distinct parts: a hardware-based Policy Decision Point (PDP) that handles security-critical decisions, and a software-based Policy Enforcement Point (PEP) that handles policy application. This segmentation allows the hardware to provide secure, high-performance decision-making while the software maintains flexibility in policy enforcement, thereby resolving the contradiction between security and flexibility.
2Ease of manufacture
If software-only solutions are used for policy-based access control, then ease of implementation is improved, but performance is worsened
Solution Approach 1:
The patent replaces the software-based policy decision-making mechanism with a hardware implementation using logic gates, multiplexers, and memory components. This substitution of the mechanical/software system with a dedicated hardware circuitry system significantly improves processing speed and performance while maintaining ease of implementation through standardized hardware design methodologies.
3Reliability
If hardware implementation is used for PDP servers, then performance and security are improved, but device complexity is worsened
Solution Approach 1:
The hardware PDP is designed with universal functionality to handle multiple security policies and access control scenarios through a single integrated circuit. The use of multiplexers and configurable logic gates allows the same hardware structure to adapt to different policy requirements, thereby reducing overall system complexity while maintaining high security standards.
4Productivity
If hardware implementation is used for PDP servers, then performance is improved, but computing resources consumption is worsened
Solution Approach 1:
The patent extracts the most computationally intensive and security-critical policy decision-making functions from the general-purpose processor and implements them in dedicated hardware circuits. This extraction allows the hardware to process security decisions with higher performance and lower power consumption compared to software execution, while the software processor can focus on less resource-intensive policy enforcement tasks.
Data Source
AI summary
A system and method for hardware implementations of policy-based secure computing environments for Internet enabled devices. The present invention facilitates a secure computing environment for any Internet enabled device where policy rules can be described as hardware components that allow or deny access to resources on the device. A compiler produces a hardware description language (HDL) of the hardware components based on given policy rules for that component. The system may be partially or completely implemented in hardware to address inherent limitations of a software only solution. The invention provides greater flexibility to the overall system in terms of performance, security, and expressiveness of the policy rules that must be executed.


