Hardware Policy Engines for Mandatory Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware and software security systems for computer systems are limited, as they rely on software mechanisms to control access to data in processor registers, which can lead to security vulnerabilities due to potential errors in the operating system software, making it difficult to ensure complete security.

Innovation Solution

Implementing hardware-based mandatory access control by associating instruction and operand access policy labels with instructions and data, and using hardware policy engines to control access, thereby reducing dependence on software correctness and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software mechanisms are used to control access to data in processor registers, then the system can operate with standard hardware, but security vulnerabilities arise due to potential errors in the operating system software

Engineering Contradiction:
ImprovesecurityVSAvoidsoftware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the software-based access control mechanism with a hardware-based mechanism. Specifically, it introduces hardware functional units and hardware policy engines that enforce access control policies directly in the processor, eliminating dependence on operating system software correctness for register access control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces hardware policy engines as intermediary components between the processor functional units and the data being accessed. These policy engines receive access requests, evaluate them against stored access control policies, and enforce the decisions, thereby mediating all data access operations at the hardware level.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware policy engines are introduced to control access, then security is enhanced, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessor architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the processor architecture by introducing distinct hardware functional units and separate policy engine components. Each functional unit that accesses data is paired with or associated with a policy engine, creating modular access control points throughout the data path, which manages complexity through structured division.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware policy engines are designed as universal components that can enforce access control policies for multiple different functional units and data types. Rather than having dedicated access control logic for each functional unit, the policy engines provide a unified, multi-functional access control mechanism that serves the entire processor.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10802990B2Hardware based mandatory access control
Publication Date: 2020.10.13 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10802990B2 patent drawing
  • US10802990B2 patent drawing
  • US10802990B2 patent drawing

AI summary

Hardware mechanisms are provided for performing hardware based access control of instructions to data. These hardware mechanisms associate an instruction access policy label with an instruction to be processed by a processor and associate an operand access policy label with data to be processed by the processor. The instruction access policy label is passed along with the instruction through one or more hardware functional units of the processor. The operand access policy label is passed along with the data through the one or more hardware functional units of the processor. One or more hardware implemented policy engines associated with the one or more hardware functional units of the processor are utilized to control access by the instruction to the data based on the instruction access policy label and the operand access policy label.