Reconfigurable Processing Architecture for Multi-Level Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing processing architectures lack sufficient reconfigurability and fail to adaptively ensure the required level of protection for data operations across different sensitivity levels, leading to inefficient and insecure data processing.

Innovation Solution

A method for designing a processing architecture that divides operations into subsets based on protection levels, generating dedicated processing blocks and units to handle each subset, with a switch mechanism to route data appropriately, ensuring each operation is performed with the necessary level of protection and eliminating redundant operations to optimize resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a processing architecture is designed to handle multiple security levels with dedicated processing blocks for each operation subset, then the level of protection for data operations is improved, but the device complexity increases due to multiple processing blocks and routing devices

Engineering Contradiction:
Improvelevel of protectionVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The processing architecture is segmented into multiple processing blocks (PB1, PB2, etc.), each dedicated to handling specific subsets of operations at particular security levels. This segmentation allows each block to be optimized for its specific security level while maintaining overall system security through hierarchical organization.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The routing device is designed as a universal component that can dynamically direct data to any processing block based on the security level and operation type. This multi-functional routing capability reduces the need for separate dedicated paths for each security level, thereby managing complexity while maintaining protection levels.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If redundant operations on data with low protection level are eliminated, then the productivity of the processing architecture is improved, but the ease of operation decreases due to the need to identify and eliminate redundancies

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidoperation design complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

Redundant operations on low-protection-level data are extracted and removed from the processing architecture. By identifying and eliminating these unnecessary operations, the system achieves higher productivity without compromising security, as the removal focuses specifically on non-critical data processing paths.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system changes the parameter of operation redundancy by dynamically adjusting which operations are executed based on data protection levels. Operations on low-protection data are marked as eliminatable, allowing the system to optimize processing efficiency by selectively executing only necessary operations based on security requirements.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP2889855B1Method for designing a reconfigurable architecture for processing a set of multi-level security operations
Publication Date: 2020.01.08 THALES SA
  • EP2889855B1 patent drawingFigure 1~2
  • EP2889855B1 patent drawingFigure 3

AI summary

The invention relates to a method for designing a processing architecture (10) comprising a step of: - generating a processing block (12) in the processing architecture (10) to be designed, the processing block (12) comprising a calculation sub-block (21) dedicated solely to the execution of the subset's operations on data to be processed by the processing block (12) whose level of protection depends on the level of protection determined for the subset of operations considered and a protection sub-block (22) suitable for ensuring the protection of the data to be processed by the processing block, and - generating at least one routing device suitable for routing the data to be processed to each processing block.