Processor Control-Flow Integrity With Latency Output Buffer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-based control-flow integrity (CFI) techniques are ineffective against code-reuse attacks, and current hardware-based CFI methods are not sufficiently secure due to limited compute power and manipulation potential of software.

Innovation Solution

A hardware-based CFI approach using a processor arrangement with a cybersecurity-monitoring engine and a controllable latency-output-buffer unit, where the cybersecurity-monitoring engine monitors execution patterns and the latency-output-buffer unit temporarily stores output until anomalies are detected, preventing malicious control flow from accessing peripherals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software-based CFI techniques are used, then implementation flexibility is improved, but security against code-reuse attacks deteriorates

Engineering Contradiction:
Improveimplementation flexibilityVSAvoidsecurity against code-reuse attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces software-based monitoring mechanisms with a hardware-based monitoring engine. The cybersecurity-monitoring engine is implemented as dedicated hardware circuitry that directly monitors processor execution patterns, eliminating the reliance on software implementations that can be manipulated or bypassed by code-reuse attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a controllable latency-output-buffer unit as an intermediary between the processor and peripheral devices. This buffer acts as a mediator that temporarily stores output data and controls its release based on security conditions, preventing direct access by malicious control flow while maintaining normal operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based CFI monitoring is implemented, then security is improved, but processing speed deteriorates due to monitoring overhead

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent pre-generates execution pattern information representing expected legitimate execution patterns before runtime. This pre-computed reference data is stored in the cybersecurity-monitoring engine, allowing for rapid comparison during execution without requiring complex real-time analysis, thus minimizing monitoring overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a simplified copy or model of the expected execution patterns in the form of pre-generated execution pattern information. Instead of analyzing every execution detail in real-time, the hardware monitor compares actual execution against this pre-computed model, significantly reducing processing requirements while maintaining security.

Inventive Principle:
Principle #26Copying

3Measurement precision

If execution monitoring is performed continuously, then detection accuracy is improved, but system performance deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent focuses monitoring efforts on specific critical aspects of execution patterns rather than analyzing all execution details uniformly. The cybersecurity-monitoring engine concentrates on detecting deviations in control flow patterns that are most indicative of attacks, applying higher monitoring intensity where needed while reducing overhead in normal execution paths.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12462017B2Processor arrangement for monitoring control-flow integrity
Publication Date: 2025.11.04 ACCEMIC TECH GMBH
  • US12462017B2 patent drawing
  • US12462017B2 patent drawing
  • US12462017B2 patent drawing

AI summary

A processor arrangement, comprising a processor under observation, hereinafter PUO, having a processing unit, which is configured to execute an application program code stored in a memory and to provide application output data via an output interface; an observation unit that is connected to the processing unit and configured to monitor execution of the application program code by the processing unit and to provide execution information indicative of an execution pattern associated with the execution of the application program code by the PUO; a cybersecurity-monitoring engine for observing the PUO, which is inaccessible by the PUO and comprises an observation input interface for receiving the execution information and an execution-monitoring unit, which is configured to perform a comparison between the received execution information and pre-generated execution pattern information and to detect an execution anomaly in the retrieved execution information, and to provide a monitoring output signal indicative of the detected execution anomaly; a controllable latency-output-buffer unit, which is also inaccessible by the PUO and comprises a buffer memory and which receives at least a part of the output data of the PUO and the monitoring output signal, and which is configured to temporarily store the received output data in the buffer memory for a pre-determined latency time span, output the temporarily stored output data from the buffer memory at the end of the latency-time span, if no monitoring output signal indicative of the detected execution anomaly has been received, and to block at least a part of the output from the buffer memory as soon as the monitoring output signal indicative of the detected execution anomaly has been received.