Secure Data Processing in Accelerators via Segmented Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The communication overhead associated with managing secure and non-secure data processing between processors and accelerators is high, especially when smaller tasks are involved, leading to performance inefficiencies due to the need for frequent intervention by secure operating systems.

Innovation Solution

A data processing apparatus with a further processing device that can operate in both secure and non-secure modes, enabling secure data processing, encryption, and storage without involving the secure operating system, allowing for efficient task suspension and resumption while maintaining data integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure data is processed by a further processing device under control of a secure operating system, then data security is maintained, but communication overhead and processing time increase significantly

Engineering Contradiction:
Improvedata securityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the processing device into secure and non-secure portions, allowing secure data to be processed in isolation within the secure portion while non-secure operations continue in the non-secure portion. This segmentation enables secure processing without requiring continuous secure operating system intervention, reducing communication overhead while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure data store as an intermediary between the secure and non-secure portions. Secure data can be stored in this intermediary store and accessed by both secure and non-secure processing portions without requiring direct communication with the secure operating system, thereby reducing overhead while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If secure data is transferred between processor and accelerator, then processing capability is increased, but communication overhead increases

Engineering Contradiction:
Improveprocessing capabilityVSAvoidcommunication overhead
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent merges the secure processing capabilities directly into the accelerator by providing a secure portion within the processing device that can perform secure operations. This merging eliminates the need for frequent data transfers between the processor and accelerator for secure operations, reducing communication overhead while maintaining enhanced processing capability.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary secure processing within the secure portion of the processing device before data needs to be transferred to or from the accelerator. By completing secure operations in advance within the secure boundary, the frequency and volume of secure data transfers are reduced, decreasing communication overhead.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8775824B2Protecting the security of secure data sent from a central processor for processing by a further processing device
Publication Date: 2014.07.08 ARM LTD
  • US8775824B2 patent drawing
  • US8775824B2 patent drawing
  • US8775824B2 patent drawing

AI summary

A data processing apparatus comprising: a data processor for processing data in a secure and a non-secure mode, said data processor processing data in said secure mode having access to secure data that is not accessible to said data processor in said non-secure mode, and processing data in said secure mode being performed under control of a secure operating system and processing data in said non-secure mode being performed under control of a non-secure operating system; and a further processing device for performing a task in response to a request from said data processor, said task comprising processing data at least some of which is secure data; wherein said further processing device is responsive to receipt of a signal to suspend said task to initiate: processing of said secure data using a secure key; and storage of said processed secure data to a non-secure data store; and is responsive to receipt of a signal to resume said task to initiate: retrieval of said processed secure data from said non-secure data store; and restoring of said processed secure data using said secure key; wherein said secure key is securely stored such that it is not accessible to other processes operating in said non-secure mode.