Hardware Policy Decision Point for Secure Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-only solutions for secure computing environments face performance limitations and security vulnerabilities, particularly in managing access to resources on Internet-connected devices operating in diverse contexts.

Innovation Solution

Implementing policy decision point (PDP) servers partially or fully in hardware using hardware description languages (HDL) such as Verilog or VHDL, incorporating logic gates, content addressable RAM, or other digital logic components to enhance performance, security, and flexibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-only solutions are used for policy-based access control, then flexibility and ease of implementation are improved, but performance and security are worsened

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the access control functionality into two distinct parts: a hardware-based Policy Decision Point (PDP) that handles security-critical decisions, and a software-based Policy Enforcement Point (PEP) that handles policy application. This segmentation allows the hardware to provide secure, high-performance decision-making while the software maintains flexibility in policy enforcement, thereby resolving the contradiction between security and flexibility.

Inventive Principle:
Principle #1Segmentation

2Ease of manufacture

If software-only solutions are used for policy-based access control, then ease of implementation is improved, but performance is worsened

Engineering Contradiction:
Improveease of implementationVSAvoidperformance
Core Design Contradiction:
Ease of manufactureVSProductivity

Solution Approach 1:

The patent replaces the software-based policy decision-making mechanism with a hardware implementation using logic gates, multiplexers, and memory components. This substitution of the mechanical/software system with a dedicated hardware circuitry system significantly improves processing speed and performance while maintaining ease of implementation through standardized hardware design methodologies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If hardware implementation is used for PDP servers, then performance and security are improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware PDP is designed with universal functionality to handle multiple security policies and access control scenarios through a single integrated circuit. The use of multiplexers and configurable logic gates allows the same hardware structure to adapt to different policy requirements, thereby reducing overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If hardware implementation is used for PDP servers, then performance is improved, but computing resources consumption is worsened

Engineering Contradiction:
ImproveperformanceVSAvoidpower consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the most computationally intensive and security-critical policy decision-making functions from the general-purpose processor and implements them in dedicated hardware circuits. This extraction allows the hardware to process security decisions with higher performance and lower power consumption compared to software execution, while the software processor can focus on less resource-intensive policy enforcement tasks.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10581852B2Hardware implementation methods and system for secure, policy-based access control for computing devices
Publication Date: 2020.03.03 SEQUITUR LABS INC
  • US10581852B2 patent drawing
  • US10581852B2 patent drawing
  • US10581852B2 patent drawing

AI summary

A system and method for hardware implementations of policy-based secure computing environments for Internet enabled devices. The present invention facilitates a secure computing environment for any Internet enabled device where policy rules can be described as hardware components that allow or deny access to resources on the device. A compiler produces a hardware description language (HDL) of the hardware components based on given policy rules for that component. The system may be partially or completely implemented in hardware to address inherent limitations of a software only solution. The invention provides greater flexibility to the overall system in terms of performance, security, and expressiveness of the policy rules that must be executed.