Interconnect Firewall Orchestration for SoC Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing device security measures, such as firewall policies, are insufficient in protecting against cyber-attacks and data loss, particularly in environments where interconnects between hardware components are not adequately secured.
Innovation Solution
The implementation of a firewall orchestration circuitry that generates and manages firewall policies at the interconnect level, allowing for a more robust and agnostic approach to security. This involves identifying hardware and interconnects, generating firewall policies, and applying them to restrict or allow operations between components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional firewall policies are used, then basic security restrictions are provided, but they are insufficient against cyber-attacks and data loss in interconnected hardware environments
Solution Approach 1:
The system segments security control at the interconnect level between hardware components, creating isolated security zones. Each interconnect is treated as a separate security boundary that can be independently controlled, allowing fine-grained access management and preventing lateral movement of threats across the hardware system.
Solution Approach 2:
The interconnect itself serves as an intermediary security mechanism between hardware components. By embedding security controls directly within the interconnect, the system creates a mediator that filters and monitors all communications between components, enabling security without requiring additional external firewall infrastructure.
2Reliability
If interconnect-level security controls are implemented, then security and privacy are enhanced, but system complexity increases
Solution Approach 1:
The security control functionality is merged with the existing interconnect hardware infrastructure. By combining security functions with the interconnect's native capabilities, the system avoids adding separate dedicated security hardware, thereby reducing overall system complexity while maintaining enhanced security protection.
Solution Approach 2:
The interconnect is designed to serve multiple functions: data communication and security control. This multi-functionality eliminates the need for separate security hardware, as the same interconnect infrastructure handles both tasks, thereby reducing system complexity while providing comprehensive security.
3Reliability
If strict transaction controls are enforced at the interconnect level, then access to resources is limited, but operational flexibility between hardware components is reduced
Solution Approach 1:
The security controls at the interconnect level are made dynamic rather than static. Access policies can be adjusted in real-time based on the operational context, allowing the system to maintain strict security when needed while providing operational flexibility when authorized. This dynamic approach enables adaptive access control that responds to changing system requirements.
Solution Approach 2:
The system changes security parameters dynamically based on operational needs. By adjusting control parameters such as allowed operations, access permissions, and transaction limits, the system can enforce strict security when required while maintaining operational flexibility during normal operations, resolving the contradiction between security and ease of operation.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, apparatus, articles of manufacture, and methods are disclosed to generate and manage a firewall policy. An example includes interface circuitry, machine readable instructions, and programmable circuitry to at least one of instantiate or execute the machine readable instructions to determine whether an operation is allowed to pass between a first component on a system-on-chip (SoC) and a second component on the SoC, detect an interconnect between the first component on the SoC and the second component on the SoC, cause the interconnect to filter the operation based on the determination of whether the operation is allowed to pass between the first component and the second component, and transmit a request to filter the operation based on the determination of whether the operation is allowed to pass between the first component and the second component.