Partition Management Unit for Computing System Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computing systems face issues with network denial of service attacks, virus and spyware software, separation of deterministic and non-deterministic software, power management, and instability related to cache data and peripheral settings, which affect security, reliability, and integrity.
Innovation Solution
A computing system equipped with a partition management unit (PMU) that allocates memory and processing time to isolate functions, including service attack monitors, virus monitors, spyware monitors, deterministic loops, and power management routines, allowing for separate partitions to manage these challenges effectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If multiple applications are operated simultaneously on a single computer system, then hardware costs, power consumption, and size are reduced, but security, integrity, and reliability are compromised due to potential interference between applications
Solution Approach 1:
The patent divides a single computer system into multiple isolated partitions, each capable of running separate applications. The partition management unit creates logical boundaries that segment the system resources (CPU, memory, I/O) among multiple applications, allowing them to coexist on one physical system while maintaining isolation similar to dedicated systems.
Solution Approach 2:
The partition management unit acts as an intermediary layer between applications and system resources. It mediates resource allocation and access control, ensuring that applications in different partitions cannot interfere with each other while still allowing controlled interaction when needed. This intermediary enforces security and reliability constraints.
2Reliability
If physical isolation is provided for each avionics function, then functional isolation and reliability are ensured, but hardware costs, power consumption, and system size increase
Solution Approach 1:
The patent merges multiple isolated computer systems into a single unified system by implementing virtual partitioning. Instead of physically separating avionics functions into dedicated hardware systems, the partition management unit creates logical isolation within one system, combining resources while maintaining the functional isolation required for reliability.
Solution Approach 2:
A single computer system is designed to perform multiple distinct avionics functions simultaneously through partitioning. The system becomes universal, capable of hosting multiple applications (autopilot, flight management, displays) on one platform, reducing the need for separate dedicated systems while maintaining the isolation necessary for each function's reliability.
3Productivity
If service requests are processed without partitioning, then system responsiveness is maintained, but network denial of service attacks can overwhelm the processor and prevent other tasks from receiving appropriate processing resources
Solution Approach 1:
The system segments processor resources into partitioned time slots and resource allocations. Service requests are handled within specific partitions with guaranteed resource allocations, preventing any single partition from consuming all processor resources. This segmentation protects against denial of service attacks by limiting the maximum resources any single application can consume.
Solution Approach 2:
The partition management unit implements feedback mechanisms that monitor resource usage and enforce partition boundaries. When a partition attempts to consume excessive resources, the PMU detects this and adjusts resource allocation to maintain fairness and prevent system overload, ensuring continuous responsiveness across all partitions.
4Adaptability or versatility
If deterministic and non-deterministic software are allowed to interact freely, then software versatility is maintained, but system stability is compromised due to unpredictable timing and fault propagation
Solution Approach 1:
The patent segments software into deterministic and non-deterministic partitions with clearly defined boundaries. Deterministic partitions guarantee timing and resource allocation for critical real-time operations, while non-deterministic partitions handle flexible applications. This segmentation allows both types of software to coexist without interfering with each other's stability requirements.
Solution Approach 2:
Different partitions are assigned different quality characteristics appropriate to their function. Deterministic partitions receive guaranteed resource allocation and strict timing constraints, while non-deterministic partitions operate with more flexibility. This local quality differentiation allows versatile software operation while maintaining system stability through appropriate constraints in critical areas.
Data Source
AI summary
A computing system includes a processor and a partition management unit (PMU). The partition management unit allocates partitions of memory and processing time. The PMU can allocate a partition for at least one of the following: 1. a service attack monitor, 2. a virus monitor, 3. a spyware monitor, and 4. a deterministic routine, the deterministic routine being in a separate partition and from a non-deterministic routine. In an alternative, with transition of control between partitions, the computing system enforces 1. a power management mode change, and 2. a preload or change to at least, one of the cache data peripheral settings or FPGA content mode change.


