Security Attributes of Initiators for SoC Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer systems lack comprehensive support for enforcing access control to system-level hardware resources, leading to inconsistent and ad-hoc management of security across different System on a Chip (SoC) designs, with no equivalent to security software for preventing unauthorized access to assets like configuration registers.
Innovation Solution
Implementing a uniform access control architecture using Security Attributes of Initiators (SAI) generated by SoC hardware, which are mapped and stored in policy registers to determine and enforce read and write access rights, along with a control policy register to manage configuration, ensuring secure access to resources across SoC fabrics.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware- and firmware-based security measures are designed on a per-system basis, then access control to system resources can be implemented, but design, debug, and validation work is replicated and security management becomes inconsistent across system designs
Solution Approach 1:
The patent introduces a universal access control architecture that can be applied across different System on Chip (SoC) designs. The architecture uses standardized components including a security manager, access control tables, and attribute storage that can be reused across multiple systems, eliminating the need to redesign security measures for each new system while maintaining reliable access control to configuration registers and other system resources.
2Reliability
If security software is used to prevent unauthorized access to files, then software-level security threats can be mitigated, but hardware-level security attacks remain unprotected
Solution Approach 1:
The patent introduces a hardware-based security manager as an intermediary component that sits between the processor and system resources. This security manager intercepts and controls access to configuration registers and other protected resources, providing hardware-level security protection complementary to software-based security measures. The security manager evaluates access requests against stored attributes and enforces access control policies, protecting against hardware-level attacks that software cannot prevent.
3Reliability
If comprehensive access control to all system resources is implemented, then security is enhanced, but system complexity and overhead increase
Solution Approach 1:
The patent implements selective access control where different security attributes and access control mechanisms are applied to different system resources based on their specific security requirements. Configuration registers receive enhanced protection through the security manager, while other resources may use standard access control mechanisms. This localized approach to security ensures that comprehensive protection is applied only where needed, reducing overall system complexity while maintaining security for critical resources.
Data Source
AI summary
A method and system for enforcing access control to system resources and assets. Security attributes associated with devices that initiate transactions in the system are automatically generated and forwarded with transaction messages. The security attributes convey access privileges assigned to each initiator. One or more security enforcement mechanisms are implemented in the system to evaluate the security attributes against access policy requirements to access various system assets and resources, such as memory, registers, address ranges, etc. If the privileges identified by the security attributes indicate the access request is permitted, the transaction is allowed to proceed. The security attributes of the initiator scheme provides a modular, consistent secure access enforcement scheme across system designs.


