Multi-role Secure Digital Processing via Dynamic Allocation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital processing systems face increased size, weight, and power (SWAP-C) requirements due to physical separation methods for secure processing, leading to underutilization of hardware components.

Innovation Solution

A digital processing system with physically separated processing circuits, each controlled by a programmable logical controller (PLC) and hypervisor, and a configuration controller that dynamically allocates processors to perform operations based on the type and mode of operation, enabling multi-role secure processing while reducing hardware needs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical separation is used to enable secure processing, then security is improved, but size, weight, and power requirements increase

Engineering Contradiction:
ImprovesecurityVSAvoidweight
Core Design Contradiction:
ReliabilityVSWeight of moving object

Solution Approach 1:

The processing system is divided into multiple physically separated processing circuits (first processing circuit and second processing circuit), each capable of independent secure processing. This segmentation enables security through physical isolation while allowing each segment to be optimized for specific functions, reducing overall system weight compared to a single monolithic secure processing unit.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each processing circuit is designed with multi-functionality to perform various secure processing operations (cryptographic operations, signal processing, etc.) depending on the operation type identified by the configuration controller. This universality reduces the need for separate dedicated hardware for each function, thereby reducing weight while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If physical separation is used to enable secure processing, then security is improved, but hardware components become underutilized

Engineering Contradiction:
ImprovesecurityVSAvoidhardware utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system employs dynamic configuration where the configuration controller identifies the type of operation and dynamically allocates processing circuits accordingly. Processing circuits can be dynamically assigned to different operations based on real-time needs, ensuring high hardware utilization while maintaining security through physical separation when required.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters by switching between different processing circuits based on the operation type. The configuration controller modifies the active processing circuit parameter dynamically, allowing the system to optimize hardware utilization by selecting the most appropriate circuit for each operation while maintaining security architecture.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If multiple processing circuits are used for different security levels, then processing capability is improved, but device complexity increases

Engineering Contradiction:
Improveprocessing capabilityVSAvoiddevice complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The configuration controller acts as an intermediary between the different processing circuits and the operations to be performed. It identifies the operation type and mediates the selection and allocation of appropriate processing circuits, simplifying the overall system architecture by providing a centralized control mechanism that manages the complexity of multiple processing circuits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11294706B1Multi-role secure digital processing
Publication Date: 2022.04.05 ROCKWELL COLLINS INC
  • US11294706B1 patent drawing
  • US11294706B1 patent drawing
  • US11294706B1 patent drawing

AI summary

A processing system includes a first processing circuit including a first PLC configured to receive a red signal, a plurality of first processors operated by the first PLC to process the red signal, and a first hypervisor configured to control operation of the first processors. The processing system includes a second processing circuit physically separated from the first processing circuit that includes a second PLC configured to receive a black signal, a plurality of second processors operated by the second PLC to process the black signal, and a second hypervisor configured to control operation of the second processors. The processing system includes a configuration controller configured to identify an operation to be performed by at least one of the first or second processing circuit and cause at least one of the corresponding first hypervisor or second hypervisor to allocate respective first processors or second processors to perform the operation.