Programmable Metadata Processing Unit for Security Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional processor architectures are inadequate for enforcing a wide range of security policies at the instruction level due to limited metadata bits and fixed policy support, leading to high overheads and inefficiencies in securing modern computer systems against evolving threats.

Innovation Solution

The Programmable Unit for Metadata Processing (PUMP) integrates a metadata tag with every memory word and register, allowing software-defined, unbounded metadata processing with hardware support for caching rules, enabling efficient enforcement of multiple security policies simultaneously without fixed bit limits.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software is used to enforce security policies, then flexibility and adaptability are improved, but runtime overhead and energy consumption increase significantly

Engineering Contradiction:
Improvepolicy flexibilityVSAvoidenergy overhead
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent merges software-defined policy flexibility with hardware-executed metadata processing. The PUMP unit is a hardware component that processes metadata tags, while the policy rules themselves are defined in software. This combination allows the system to enjoy the adaptability of software-defined policies while achieving the low overhead of hardware execution for metadata propagation and checking.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If hardware is used to enforce security policies, then runtime performance is improved, but adaptability and ease of deployment are reduced

Engineering Contradiction:
Improveruntime performanceVSAvoidpolicy adaptability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic policy enforcement by allowing policy rules to be defined and updated in software while being executed by dedicated hardware. The PUMP unit can adapt to different policies by loading new rule sets from software, enabling the hardware to maintain high performance while becoming adaptable to evolving security requirements without requiring physical hardware changes.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If fixed bit allocation is used for metadata, then hardware area and complexity are reduced, but the ability to support diverse policies is limited

Engineering Contradiction:
Improvehardware complexityVSAvoidpolicy support capability
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal metadata tag structure that can accommodate diverse policy requirements. The metadata tags use a standardized format with fields that can represent different types of security attributes (ownership, integrity, confidentiality, etc.). This universal structure allows the same hardware PUMP unit to enforce multiple different policies without requiring separate hardware paths, achieving versatility without proportional increases in complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If unbounded metadata is supported, then policy expressiveness is improved, but hardware area and memory overhead increase

Engineering Contradiction:
Improvepolicy expressivenessVSAvoidhardware area
Core Design Contradiction:
Adaptability or versatilityVSArea of stationary object

Solution Approach 1:

The patent implements a nested metadata structure where compact tags serve as pointers to more detailed policy information stored in external memory. The hardware PUMP unit processes only the compact tags, which contain essential security attributes, while detailed policy definitions are stored externally and accessed only when needed. This nesting allows unbounded policy expressiveness while keeping the critical hardware path area minimal.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10719630B2Programmable unit for metadata processing
Publication Date: 2020.07.21 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • US10719630B2 patent drawing
  • US10719630B2 patent drawing
  • US10719630B2 patent drawing

AI summary

A system and method for metadata processing that can be used to encode an arbitrary number of security policies for code running on a stored-program processor. This disclosure adds metadata to every word in the system and adds a metadata processing unit that works in parallel with data flow to enforce an arbitrary set of policies, such that metadata is unbounded and software programmable to be applicable to a wide range of metadata processing policies. This instant disclosure is applicable to a wide range of uses including safety, security, and synchronization.