M-CDS Shared Memory Buffers for Low-Latency Domain Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems face challenges in efficiently managing data transfer and isolation between different hardware domains within a data center, particularly in edge computing environments, where security and latency are critical, and traditional centralized cloud computing solutions are inadequate.

Innovation Solution

Implementing a memory-based cross-domain solution (M-CDS) device that includes a shared memory region and a cross-domain solutions manager to create buffers for controlled data transmission between hardware blocks, enforcing isolation and adhering to predefined security policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional centralized cloud computing solutions are used, then data transfer between hardware domains can be achieved, but latency is high and security isolation is insufficient

Engineering Contradiction:
Improvesecurity isolationVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a memory-based cross-domain solution (M-CDS) device as an intermediary component between isolated hardware domains. This M-CDS device includes a shared memory region that enables controlled data transfer between domains while maintaining isolation boundaries, thus achieving both security (reliability) and low latency by providing direct memory access without centralized cloud mediation

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the computing environment into isolated hardware domains with distinct security boundaries. Each domain can be independently managed and protected, while the M-CDS device provides controlled inter-domain communication. This segmentation enables security isolation while the direct memory interface maintains low latency

Inventive Principle:
Principle #1Segmentation

2Reliability

If domain isolation is enforced for security, then security policies are maintained, but data transfer efficiency between domains decreases

Engineering Contradiction:
Improvesecurity policy complianceVSAvoiddata transfer efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The M-CDS device serves as a specialized intermediary that enables efficient data transfer between isolated domains while enforcing security policies. The shared memory region provides direct memory access for high-speed transfer, and the cross-domain solution manager acts as a policy enforcement point that monitors and controls access without blocking performance

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the parameters of inter-domain communication by providing direct memory access interfaces with controlled access permissions. This allows data to be transferred at memory speeds rather than through slower centralized processing, while access control parameters ensure security policy compliance

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250245168A1Isolated compute domains in a computing device
Publication Date: 2025.07.31 INTEL CORP
  • US20250245168A1 patent drawing
  • US20250245168A1 patent drawing
  • US20250245168A1 patent drawing

AI summary

A device includes a plurality of hardware block and an interconnect network to interconnect the plurality of hardware blocks, where the interconnect network includes a memory-based cross-domain solutions (M-CDS) device. The M-CDS device includes a shared memory region and a cross-domain solutions (CDS) manager to create a buffer in the shared memory region to restrict transmission of data through the buffer to a subset of the plurality of hardware blocks based on the set of policies, where the buffer is to enforce isolation of the subset of hardware blocks from another subset of the plurality of hardware blocks