Defense-in-Depth Hierarchy for IoT Execution Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current integrated circuit technologies lack a robust defense-in-depth mechanism to securely manage and isolate different functions within IoT devices, leading to potential vulnerabilities in network connectivity, storage, and other critical operations.

Innovation Solution

The implementation of a hybrid chip with a defense-in-depth hierarchy of independent execution environments, where functions like power, storage, and Wi-Fi are assigned to different layers based on trust levels, with lower-trusted environments restricted from direct access and requiring requests from higher-trusted environments for execution.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unified execution environment is used in IoT devices, then device complexity is reduced and ease of operation is improved, but security and reliability deteriorate due to lack of isolation between functions

Engineering Contradiction:
ImprovesecurityVSAvoidexecution environment structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into multiple independent execution environments (first, second, and third execution environments) with different trust levels. Each environment is isolated and can only access specific functions appropriate to its trust level, preventing unauthorized access between functions while maintaining clear security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A function assignment mechanism acts as an intermediary that controls access between execution environments and functions. The system assigns functions to specific execution environments based on trust levels, and lower-trusted environments must request access through this intermediary mechanism, providing controlled interaction without direct access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple independent execution environments with defense-in-depth hierarchy are implemented, then security and reliability are improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The integrated circuit is segmented into distinct execution environments with clearly defined trust levels and access permissions. This segmentation allows for modular design and manufacturing, where each environment can be independently configured and validated, reducing overall manufacturing complexity despite the increased security architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10715526B2Multiple cores with hierarchy of trust
Publication Date: 2020.07.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10715526B2 patent drawing
  • US10715526B2 patent drawing
  • US10715526B2 patent drawing

AI summary

The disclosed technology is generally directed to integrated circuit technology with defense-in-depth. In one example of the technology, an integrated circuit includes a set of independent execution environments including at least two independent execution environments. At least two of the independent execution environments are general purpose cores with differing capabilities. The independent execution environments in the set of independent execution environments are configured to have a defense-in-depth hierarchy.