Processor Core Segmentation for Secure Dump Events
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Diagnostic and debugging operations often capture sensitive data during dump events, exposing it to unauthorized access, which can lead to security breaches and legal liabilities due to their agnostic handling of data types.
Innovation Solution
Designate specific processor cores and memory components for handling sensitive data and exclude them from data captures during dump events to prevent unauthorized access, using a service module to manage data capture and ensure only non-sensitive data is captured from other cores and memory components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of information
If diagnostic and debugging operations capture all data during dump events, then complete system state information is obtained for analysis, but sensitive data is exposed to unauthorized access
Solution Approach 1:
The system divides processor cores into two distinct segments: sensitive data processor cores and non-sensitive data processor cores. This segmentation allows the dump operation to capture complete system state information from non-sensitive cores while excluding sensitive cores, thereby obtaining comprehensive diagnostic data without exposing sensitive information to unauthorized access
Solution Approach 2:
The invention extracts sensitive data processor cores from the general data capture process. During a dump event, the service module identifies and excludes designated sensitive cores from the data capture operation, removing the harmful element (sensitive data) from the information flow while preserving the diagnostic capability for non-sensitive system state information
2Ease of operation
If all processor cores are included in data capture during dump events, then complete debugging information is obtained, but unauthorized access to sensitive data becomes possible
Solution Approach 1:
Processor cores are segmented into sensitive and non-sensitive categories with clear designation. This segmentation enables the debugging operation to proceed easily by capturing data from non-sensitive cores while automatically excluding sensitive cores, maintaining both operational ease and security reliability
Solution Approach 2:
The service module acts as an intermediary between the dump event trigger and the data capture process. It receives the dump event, identifies designated sensitive processor cores, and controls the data capture operation to exclude these cores while including others, thereby mediating between complete debugging information needs and data security requirements
3Reliability
If sensitive data processor cores are excluded from data capture, then data security is maintained, but complete system state information is lost
Solution Approach 1:
By segmenting processor cores into sensitive and non-sensitive groups, the system maintains data security by excluding only the necessary sensitive cores from capture, while preserving complete system state information from all non-sensitive cores and other relevant sources, thus avoiding unnecessary loss of diagnostic information
4Ease of operation
If diagnostic operations handle all data uniformly, then operational simplicity is maintained, but sensitive data protection cannot be implemented
Solution Approach 1:
The system applies different quality characteristics to different processor cores: sensitive data processor cores are designated with special security attributes while non-sensitive cores use standard handling. This local differentiation allows the majority of data handling operations to remain simple and uniform, while selectively applying enhanced protection only where needed, thus maintaining operational simplicity overall while preventing sensitive data exposure
Data Source
AI summary
Embodiments provided in this disclosure include a method, computer program product, and system for protecting sensitive data in a processing system comprising a plurality of processor cores. The method includes designating at least one processor core for processing sensitive data, and during a dump event, capturing data from each of the plurality of processor cores except the designated processor core to prevent unauthorized access to sensitive data.


