Parallel Processor Core Security Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems with parallel processors lack secure operation methods to effectively execute both secure and non-secure application programs simultaneously, leading to difficulties in error detection and system reliability, particularly in critical sectors like railways.
Innovation Solution
A method where one processor core operates securely and another core operates non-securely, allowing for easy detection of errors by comparing memory contents and execution results, ensuring that non-secure application programs do not affect secure operations, and utilizing multiple processor cores with different operating systems to enhance error detection and hardware integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If non-secure application programs are executed in a computer system with parallel processors, then the system can perform general-purpose computing tasks, but error detection capability deteriorates because errors in non-secure programs cannot be easily distinguished from secure operations
Solution Approach 1:
The computer system is segmented into multiple processor cores with different security levels. Secure processor cores execute only secure application programs with guaranteed error detection, while non-secure processor cores execute non-secure application programs. This segmentation allows the system to maintain both security-critical operations and general-purpose computing simultaneously, with errors in non-secure programs easily detectable because they occur in isolated, clearly defined non-secure cores.
2Reliability
If all processor cores are operated securely to ensure system reliability, then error detection and system security are improved, but the ability to execute non-secure application programs deteriorates
Solution Approach 1:
Different processor cores are assigned different security qualities locally. Some cores are configured as secure processor cores with strict security protocols and error detection mechanisms, while other cores are configured as non-secure processor cores for general-purpose computing. This local differentiation allows each core to operate with the appropriate security level for its intended workload, maintaining high reliability for critical operations while enabling flexibility for non-secure tasks.
3Productivity
If multiple processor cores are used to increase computing capacity, then productivity is improved, but system complexity increases making secure operation more difficult
Solution Approach 1:
The multi-core processor system is segmented into secure and non-secure processor cores with clearly defined operational boundaries. Each secure processor core operates independently with dedicated secure application programs, while non-secure cores handle general computing tasks. This segmentation simplifies system operation by providing clear separation of concerns, making it easier to manage and verify security-critical operations even in a multi-core environment.
Solution Approach 2:
Instead of making all processor cores secure and trying to manage complexity, the system inverts the approach by explicitly designating certain cores as non-secure. This inversion simplifies the security model by reducing the number of cores that require complex security management, while still providing secure computing capacity where needed.
Data Source
AI summary
A method for operating a computer system including identical first and second processors operated in parallel and having at least two processor cores each, includes operating one processor core of each processor securely based on a secure operating system achieving or exceeding a specified security level, each executing at least one application program securely by achieving the specified security level. The processor cores securely execute the same application program or programs. Remaining processor cores of the first processor are switched off or operated securely, based on the secure operating system or one or more other secure operating systems under the secure execution of the same and/or other application programs. At least one processor core in the second processor is operated nonsecurely based on a nonsecure operating system not achieving the specified security level and executes at least one application program nonsecurely, falling short of the specified security level.


