Policy Governor Dynamic Security Policy Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing systems face challenges in securely activating functionality with flexible, yet secure, low overhead and cost, due to inefficiencies in security asset usage and static security policies.

Innovation Solution

A data processing system with a security subsystem that includes a policy governor to dynamically adjust security policies during runtime, ensuring coherence with system state and security status, and allowing for fail-operational modes and flexible key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static security policy is used, then security integrity is maintained, but system flexibility and adaptability to runtime conditions are reduced

Engineering Contradiction:
Improvesecurity integrityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic security policy system where the Policy Governor can modify security policies at runtime based on system state changes, security events, or administrator commands. This allows the security policy to transition from static to dynamic, enabling the system to adapt to changing conditions while maintaining security integrity through controlled policy adjustments.

Inventive Principle:
Principle #15Dynamics

2Loss of energy

If security assets are used only during system initialization, then security overhead is reduced, but security functionality is unavailable during runtime operations

Engineering Contradiction:
Improvesecurity overheadVSAvoidsecurity functionality availability
Core Design Contradiction:
Loss of energyVSProductivity

Solution Approach 1:

The patent performs preliminary actions by establishing a secure boot process and initializing security assets during system startup. The Policy Governor is pre-configured with initial security policies before runtime operations begin, allowing security functionality to be ready for immediate use without requiring continuous heavy computational overhead during normal operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing the Policy Governor to automatically adjust security policies based on detected security events or system state changes without requiring manual intervention. This automated approach maintains security functionality during runtime while minimizing the need for continuous manual security management.

Inventive Principle:
Principle #25Self-service

3Reliability

If a hierarchical trust model with sequential initialization is used, then security authenticity is ensured, but system complexity and initialization time are increased

Engineering Contradiction:
Improvesecurity authenticityVSAvoidinitialization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security initialization process into distinct phases: secure boot phase for verifying authenticity, policy establishment phase for configuring security policies, and runtime operation phase for executing with adjusted policies. This segmentation allows the hierarchical trust model to maintain security authenticity while reducing overall initialization complexity by separating critical security operations from general system initialization.

Inventive Principle:
Principle #1Segmentation

4Device complexity

If security policies are fixed until system reboot, then implementation simplicity is maintained, but response time to security events is delayed

Engineering Contradiction:
Improveimplementation simplicityVSAvoidresponse time to security events
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The patent introduces dynamics to the security policy system by enabling the Policy Governor to modify policies in response to security events during runtime. When a security event is detected, the system can dynamically adjust the relevant security policy without requiring a complete system reboot, thereby reducing response time while maintaining relatively simple implementation through automated policy enforcement mechanisms.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3933630B1Method and apparatus to adjust system security policies based on system state
Publication Date: 2025.04.16 NXP BV
  • EP3933630B1 patent drawingFigure 1
  • EP3933630B1 patent drawingFigure 2~3
  • EP3933630B1 patent drawingFigure 4~5

AI summary

A system, method, and apparatus are provided for securely controlling operations of a data processing system in which security subsystem is activated to provide security services by responding to a security service request, evaluating the request against an adjustable set of system security policies to determine if the security service request is granted access to a protected asset, by generating a response to the security service request using the protected asset if the security service request is granted access to the protected asset, by adjusting a security access policy for the protected asset in the adjustable set of system security policies, and by sending the response from the security subsystem to the external application subsystem.