Processor Core Segmentation for Secure Dump Events

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Diagnostic and debugging operations often capture sensitive data during dump events, exposing it to unauthorized access, which can lead to security breaches and legal liabilities due to their agnostic handling of data types.

Innovation Solution

Designate specific processor cores and memory components for handling sensitive data and exclude them from data captures during dump events to prevent unauthorized access, using a service module to manage data capture and ensure only non-sensitive data is captured from other cores and memory components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If diagnostic and debugging operations capture all data during dump events, then complete system state information is obtained for analysis, but sensitive data is exposed to unauthorized access

Engineering Contradiction:
Improvesystem state informationVSAvoiddata security breach
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The system divides processor cores into two distinct segments: sensitive data processor cores and non-sensitive data processor cores. This segmentation allows the dump operation to capture complete system state information from non-sensitive cores while excluding sensitive cores, thereby obtaining comprehensive diagnostic data without exposing sensitive information to unauthorized access

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The invention extracts sensitive data processor cores from the general data capture process. During a dump event, the service module identifies and excludes designated sensitive cores from the data capture operation, removing the harmful element (sensitive data) from the information flow while preserving the diagnostic capability for non-sensitive system state information

Inventive Principle:
Principle #2Taking out (Extraction)

2Ease of operation

If all processor cores are included in data capture during dump events, then complete debugging information is obtained, but unauthorized access to sensitive data becomes possible

Engineering Contradiction:
Improvedebugging operationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

Processor cores are segmented into sensitive and non-sensitive categories with clear designation. This segmentation enables the debugging operation to proceed easily by capturing data from non-sensitive cores while automatically excluding sensitive cores, maintaining both operational ease and security reliability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service module acts as an intermediary between the dump event trigger and the data capture process. It receives the dump event, identifies designated sensitive processor cores, and controls the data capture operation to exclude these cores while including others, thereby mediating between complete debugging information needs and data security requirements

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If sensitive data processor cores are excluded from data capture, then data security is maintained, but complete system state information is lost

Engineering Contradiction:
Improvedata securityVSAvoidsystem state information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

By segmenting processor cores into sensitive and non-sensitive groups, the system maintains data security by excluding only the necessary sensitive cores from capture, while preserving complete system state information from all non-sensitive cores and other relevant sources, thus avoiding unnecessary loss of diagnostic information

Inventive Principle:
Principle #1Segmentation

4Ease of operation

If diagnostic operations handle all data uniformly, then operational simplicity is maintained, but sensitive data protection cannot be implemented

Engineering Contradiction:
Improvedata handling operationVSAvoidsensitive data exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies different quality characteristics to different processor cores: sensitive data processor cores are designated with special security attributes while non-sensitive cores use standard handling. This local differentiation allows the majority of data handling operations to remain simple and uniform, while selectively applying enhanced protection only where needed, thus maintaining operational simplicity overall while preventing sensitive data exposure

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10387668B2Data protected process cores
Publication Date: 2019.08.20 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10387668B2 patent drawing
  • US10387668B2 patent drawing
  • US10387668B2 patent drawing

AI summary

Embodiments provided in this disclosure include a method, computer program product, and system for protecting sensitive data in a processing system comprising a plurality of processor cores. The method includes designating at least one processor core for processing sensitive data, and during a dump event, capturing data from each of the plurality of processor cores except the designated processor core to prevent unauthorized access to sensitive data.