Resource Group Auditor for NoC Access Control Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Validating the correct configuration of access control schemes in computing devices with complex network-on-chip (NoC) fabrics is challenging due to numerous paths and protection units, often requiring manual validation late in the design cycle, leading to increased costs and complexity.
Innovation Solution
A system and method for auditing resource groups across protection units, involving a resource group auditor that obtains and assesses paths to identify unsecured and path-violation-free paths, generating a report to facilitate corrective actions and ensure proper access control implementation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual validation of access control configuration is performed, then validation accuracy can be ensured, but validation time and cost increase significantly
Solution Approach 1:
The patent replaces manual validation (mechanical human operation) with an automated validation system that uses computational algorithms to assess access control configurations. The system automatically traverses device fabric paths, evaluates protection unit settings, and generates validation reports without human intervention, thereby maintaining accuracy while dramatically reducing validation time.
Solution Approach 2:
The validation system performs self-assessment of the access control configuration by automatically examining protection units and paths. The system serves itself by autonomously identifying configuration errors, generating validation results, and providing feedback without requiring external manual validation, thus eliminating time loss while maintaining precision.
2Reliability
If comprehensive path assessment is performed across all protection units, then access control validity can be ensured, but system complexity and computational resources increase
Solution Approach 1:
The patent segments the complex validation task into distinct components: path identification, protection unit assessment, configuration evaluation, and report generation. By dividing the comprehensive path assessment into manageable segments, the system ensures thorough validation of access control validity while reducing overall system complexity through modular processing.
Solution Approach 2:
The validation system introduces an intermediary automated assessment layer between the device fabric and the validation process. This intermediary automatically traverses paths, evaluates protection units, and translates complex configuration data into interpretable validation results, ensuring reliability while managing complexity through automated mediation.
3Adaptability or versatility
If validation is performed late in the design cycle, then design flexibility is maintained, but corrective action costs increase
Solution Approach 1:
The patent performs access control configuration validation as a preliminary action during the design cycle, before final implementation. By validating configurations early, the system identifies errors when they are still easy and inexpensive to correct, maintaining design flexibility while reducing corrective action costs through proactive detection.
Solution Approach 2:
The validation system performs preliminary anti-action by identifying and flagging configuration errors before they propagate through the design process. By detecting invalid access control configurations in advance, the system prevents costly corrective actions later, maintaining design adaptability while reducing manufacturing complexity through early error prevention.
Data Source
AI summary
Systems and techniques are described herein for assessing paths between components and access control configurations or entities along paths. For example, a computing device (e.g., implementing a resource group auditor) can obtain a set of paths from access domains to targets. The computing device can assess the set of paths to obtain a first subset of the set of paths that are unsecured. The computing device can further assess a first portion of the set of paths that include one or more protection units to obtain a second subset of the set of paths that are path violation free. The computing device can assess a second portion of the set of paths that include the protection unit(s) to obtain a third subset of the set of paths that include a path violation. The computing device can generate a report that includes the first subset and the third subset.


