Remapping Interconnect Access Requests for Tenant Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing and distributed computing environments face challenges in protecting host system resources from malicious or poorly designed applications, as existing access control methods lack effective mechanisms to securely manage and isolate resources across multiple tenants.

Innovation Solution

The implementation of independently configurable access control devices that process access requests via an interconnect, allowing both host and user applications to configure access controls, enabling hardware-based security features such as remapping and interleaving to isolate resources and enhance performance without conflicts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If access control is implemented to protect host system resources from malicious applications, then security is improved, but device complexity increases due to the need for independently configurable access control devices and remapping stages

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The access control device is segmented into multiple independently configurable stages, including remapping stages and interleaving stages. Each stage can be independently configured to perform specific access control functions, allowing complex security requirements to be broken down into manageable, modular components that can be configured and managed separately

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access control device employs dynamically configurable remapping and interleaving stages that can be adjusted at runtime. Configuration parameters such as remap parameters, bitmask values, and interleaving factors can be modified without resetting the entire device, enabling adaptive security policies that respond to changing threat landscapes while maintaining operational continuity

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If independently configurable access control devices are deployed to allow both host and user applications to configure access controls, then adaptability is improved, but device complexity increases due to multiple configuration interfaces and stages

Engineering Contradiction:
ImproveadaptabilityVSAvoiddevice complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The access control device is designed with universal configuration capabilities that serve multiple purposes. The same remapping and interleaving stages are used by both host applications and user applications, with each entity having its own configurable parameters. This multi-functional design allows a single device structure to fulfill diverse access control requirements without requiring separate hardware for each application type

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The configuration space is segmented into distinct host-configurable parameters and user-configurable parameters. Each segment can be independently managed by its respective application type, allowing host applications to configure system-wide security policies while user applications can configure application-specific access patterns without interfering with each other's configuration spaces

Inventive Principle:
Principle #1Segmentation

3Reliability

If hardware-based security features such as remapping and interleaving are implemented to isolate resources, then security is improved, but manufacturing precision requirements increase due to the need for exact parameter matching and configuration

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing precision
Core Design Contradiction:
ReliabilityVSManufacturing precision

Solution Approach 1:

The remapping and interleaving parameters are implemented as dynamically configurable values rather than fixed hardware constants. Configuration parameters including remap base addresses, bitmask patterns, and interleaving factors can be programmed and adjusted through standard interfaces, eliminating the need for precision manufacturing of specific parameter values and allowing flexible adaptation to different security requirements

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The device enables runtime changes to remapping and interleaving parameters without requiring hardware reconfiguration or manufacturing adjustments. Configuration parameters can be modified through software interfaces, allowing the system to adapt to different security policies, application requirements, and threat scenarios while maintaining consistent hardware manufacturing specifications

Inventive Principle:
Principle #35Parameter changes

4Reliability

If access control processing is added to process access requests via interconnect, then security is improved, but loss of time increases due to additional processing stages for remapping and interleaving

Engineering Contradiction:
ImprovesecurityVSAvoidloss of time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The access control device performs remapping and interleaving operations in advance of actual data access operations. By pre-configuring remap parameters, bitmask values, and interleaving factors before access requests are processed, the device eliminates the need for complex runtime calculations, reducing processing latency while maintaining security isolation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control processing is segmented into parallel stages that can operate independently and simultaneously. The remapping stage and interleaving stage are separated into distinct functional units that can process different aspects of access requests in parallel, reducing overall processing time compared to sequential execution while maintaining the security benefits of both operations

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11175839B1Independently configurable remapping for interconnect access requests
Publication Date: 2021.11.16 AMAZON TECH INC
  • US11175839B1 patent drawing
  • US11175839B1 patent drawing
  • US11175839B1 patent drawing

AI summary

Access control request parameter remapping may be implemented that supports user-configurable and host-configurable processing stages. A request may be received and evaluated to determine user-configured remapping is applied, host-configured remapping is applied or both user and host remapping applied. For applied remapping, an unmasked portion of a parameter of the access request may be replaced with a corresponding portion of a remap parameter.