Multi-tier Security Framework for Persistent Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The convergence of computing and storage functions in nonvolatile memory (NVM) devices introduces new security challenges, as data-in-use becomes vulnerable to unauthorized access, differing from traditional systems with separate volatile memory and storage, requiring a multi-tier security framework to manage access rights across multiple levels of application and storage resources in a multi-tenant environment.

Innovation Solution

A multi-tier security framework is implemented across converged server and storage infrastructures, using a PM control module to control access between processors, persistent memory devices, and nonvolatile memory, with a PM array controller and PM device controller managing access permissions and encryption to ensure secure data handling across multiple tiers and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If computing and storage functions are merged into the same hardware infrastructure, then productivity and resource utilization are improved, but security vulnerabilities increase due to unauthorized access risks

Engineering Contradiction:
Improveresource utilizationVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the security management system into multiple hierarchical tiers (application tier, OS tier, firmware tier, hardware tier), with each tier having independent security controls and access policies. This segmentation allows the system to maintain unified computing-storage hardware while implementing layered security boundaries that prevent unauthorized access propagation across different functional levels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces security intermediaries including security agents, policy enforcement points, and authentication services that mediate between applications and persistent memory resources. These intermediaries verify access rights, enforce security policies, and manage credentials, thereby protecting the converged hardware infrastructure from unauthorized access while maintaining efficient resource utilization.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple applications share the same persistent memory infrastructure, then productivity is improved through resource consolidation, but security complexity increases due to access control management

Engineering Contradiction:
Improveresource consolidationVSAvoidaccess control management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements universal security mechanisms that operate across multiple applications and memory tiers simultaneously. Security agents, authentication services, and policy enforcement points provide multi-functional capabilities that handle access control for diverse applications sharing persistent memory, thereby reducing the overall complexity compared to implementing separate security systems for each application.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent adds hierarchical dimensions to access control management by introducing multi-tier security layers (application, OS, firmware, hardware) and multi-tenant isolation levels. This dimensional approach organizes complex access control relationships into structured hierarchies, making security management more systematic and less complex than flat, application-by-application control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Productivity

If data is made persistent in the same hardware as computing functions, then productivity is improved through faster access, but security risks worsen as data-in-use becomes vulnerable to attacks

Engineering Contradiction:
Improvedata access speedVSAvoiddata vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security actions including pre-computation of cryptographic hashes, pre-establishment of security contexts, and pre-validation of access credentials before data access operations. Security agents prepare protective measures in advance, and authentication services establish secure contexts beforehand, enabling fast data access from persistent memory while maintaining security protections against vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where security agents continuously monitor data access patterns, detect anomalies, and dynamically adjust security controls. The system provides real-time feedback on access attempts, validates operations against security policies, and responds to potential threats by modifying access permissions or initiating protective actions, thereby protecting vulnerable data-in-use while maintaining fast access performance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS10318767B2Multi-tier security framework
Publication Date: 2019.06.11 HEWLETT PACKARD ENTERPRISE DEV LP
  • US10318767B2 patent drawing
  • US10318767B2 patent drawing
  • US10318767B2 patent drawing

AI summary

A security framework for a multi-tenant, multi-tier computer system with embedded processing is described. A multi-tenant security framework is created for a combined processing and storage hierarchy of multiple tiers. The multi-tenant security framework is applied to multiple execution levels of the memory device. The multi-tenant security framework is applied to multiple layers of application server software of the memory device. The multi-tenant security framework is also applied to multiple layers of storage server software of the memory device.