Inter-Processor Access Control via Exclusive Write Permissions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current inter-processor communication systems face complexity and power usage increases due to additional security measures, such as dynamic hardware access control, which can lead to performance overhead and inefficiency.
Innovation Solution
The implementation of additional configuration fields in access control rules, allowing the sending processor to specify exclusive write permissions for memory regions, thereby reducing the need for a trusted third processor to configure hardware access control and minimizing unnecessary processor wake-ups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dynamic hardware access control is implemented for inter-processor communications, then security is improved, but device complexity and power usage increase
Solution Approach 1:
The access control configuration is segmented into multiple independent fields within access control rules. Each field controls a specific aspect of memory access permissions, allowing fine-grained control without requiring complex centralized control logic. This segmentation enables the system to achieve high security through simple, modular rule configurations.
Solution Approach 2:
The access control hardware automatically enforces permissions based on configuration fields without requiring intervention from a trusted third processor. The sending processor directly configures the access control rules by setting appropriate fields, and the hardware autonomously prevents unauthorized writes, eliminating the need for additional processing overhead and reducing system complexity.
2Reliability
If a trusted third processor is used to configure hardware access control, then security is improved, but processing overhead and power consumption increase
Solution Approach 1:
The configuration function is extracted from the trusted third processor and directly assigned to the sending processor. The sending processor sets specific configuration fields in the access control rules to establish exclusive write permissions, eliminating the need for the trusted third processor to wake up and perform configuration operations, thereby reducing power consumption and processing overhead.
3Reliability
If exclusive write permissions are assigned to specific processors, then security against malicious attacks is improved, but access control configuration complexity increases
Solution Approach 1:
Different fields within the access control rules serve different local functions: some fields identify the memory region, others specify which processors have read permissions, and specific fields indicate which processor has exclusive write permission. This local differentiation of field functions allows the system to achieve comprehensive security control through a standardized, systematic configuration approach rather than complex centralized management.
Data Source
AI summary
Methods, systems, and devices for access control configurations for inter-processor communications are described to support reconfiguration of a dynamic access control configuration at a device. For example, additional configuration fields may be added to existing access control rules of the device, where these additional fields may be configured by a processor sending information to a receiving processor, via a shared memory resource or region of the device. The additional fields may include a read-only value which may specify a processor which has exclusive write permission for a memory region of the share memory. This value may indicate the sending processor of the memory region, and the value may be set by access control hardware when the additional field is changed. Other processors of the device may be prevented from writing to the memory region.


