Hierarchical System Firewall for SoC Security Policy Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hardware firewall designs for systems on chip (SoC) employ a single-hierarchy management structure, leading to increased design complexity and difficulty in meeting diverse security requirements as the number of subsystems grows.
Innovation Solution
A hierarchical system firewall is introduced, comprising a root security manager, second-level security managers, a firewall controller, and a firewall, which simplifies security policy management by dividing the system into domain clusters and assigning specific security managers to each cluster.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single-hierarchy management structure is employed, then the system can be managed with a single security manager, but the design complexity of security policies increases dramatically as the number of subsystems increases
Solution Approach 1:
The patent divides the single-hierarchy management structure into multiple hierarchical levels (root security manager at level 0, domain security managers at level 1, and subsystem security managers at level 2). Each level manages security policies for specific domains or subsystems, segmenting the previously monolithic security management function into manageable units that can independently handle diverse security requirements without increasing overall system complexity.
2Ease of operation
If a single-hierarchy management structure is employed, then the security manager can manage the entire system, but the coupling of security policy management among subsystems increases
Solution Approach 1:
The patent segments security policy management authority across multiple hierarchical levels, where each domain security manager operates independently within its domain. This segmentation reduces inter-subsystem coupling by allowing each manager to handle security policies locally without requiring coordination with all other subsystems, while the hierarchical structure maintains overall system coherence through defined reporting and policy inheritance relationships.
3Reliability
If a single-hierarchy management structure is employed, then system-wide security can be maintained, but the interference among subsystems increases
Solution Approach 1:
The patent implements segmentation of security management into hierarchical levels where each level operates semi-independently. Domain security managers at level 1 manage security for their respective domains with autonomy from other domains, reducing interference. The root security manager at level 0 maintains system-wide security policies and coordinates between domains, ensuring overall security consistency while allowing local independence that minimizes subsystem interference.
Data Source
AI summary
A hierarchical system firewall, comprising a root security manager, secondary security managers, a firewall controller, and firewalls. The root security manager designates a secondary security manager and allocates a system resource for each domain cluster, and provides firewall configuration schemes between the domain clusters. The secondary security managers add domain identifiers for hosts and devices of domain clusters, and provides a firewall configuration scheme for each domain. The firewall controller adds domain cluster identifiers for the hosts and devices in the system, and adds identification for the secondary security managers; allocates domain identification for a host and a device of a current domain cluster; and configures access permissions for the firewall of each device in the current domain cluster. The firewalls perform permissions control for access to a current device by hosts from different domains or different domain clusters. Further provided in the present invention is a configuration method for the hierarchical system firewall, simplifying system design, and improving system security.

