Secure Initial State in Integrated Safety Security Processing Platform
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The challenge lies in reconciling the operational requirements between safety and security domains in processing platforms that simultaneously perform safety-critical and high assurance security functions, particularly in reducing size, weight, and power requirements while ensuring a secure initial state.
Innovation Solution
A method involving a power-on self-test (POST) to determine the operational state of hardware sub-components and error detection states, followed by initializing and configuring safety and security monitoring functions using specific configuration data to achieve a secure initial state, ensuring compliance with operational requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physically separated federated systems are utilized to handle safety or security functions, then security and safety requirements are met, but size, weight, and power requirements increase
Solution Approach 1:
The patent combines previously separate safety-critical and high assurance security functions into a single integrated processing platform. The common hardware architecture allows both DO-178B/DO-254 certified safety functions and EAL 6 certified security functions to coexist on the same physical platform, reducing overall size, weight, and power while maintaining certification requirements through virtualization and isolation mechanisms
Solution Approach 2:
The processing platform is designed with universal hardware resources that can serve multiple functions - both safety-critical operations and high assurance security operations. The platform uses shared computational, storage, and I/O resources that are dynamically allocated and isolated through virtualization, allowing a single platform to replace multiple dedicated systems
2Weight of moving object
If safety-critical functions and high assurance security functions are performed on common hardware, then size, weight, and power requirements are reduced, but reconciliation of operational requirements between safety and security domains becomes challenging
Solution Approach 1:
The patent segments the common hardware platform into isolated execution environments or virtual machines, where safety-critical functions operate in one segmented space and high assurance security functions operate in another segmented space. Each segment maintains its own certified operational requirements (DO-178B for safety, EAL 6 for security) while sharing the underlying hardware resources through controlled interfaces
Solution Approach 2:
The patent introduces intermediary mechanisms such as hypervisors, virtualization layers, or trusted execution environments that mediate between the safety and security domains. These intermediaries manage resource allocation, enforce isolation boundaries, and coordinate operations between the two domains, simplifying the reconciliation of their different operational requirements
Data Source
AI summary
A method including initializing the processing platform, wherein initializing the processing platform includes performing a power on self-test (POST) configured to determine an operational state of one or more hardware sub-components of the processing platform, the POST further configured to determine an error detection state of one or more monitoring functions of the processing platform, initializing a safety monitoring function of the processing platform, analyzing one or more results of the POST utilizing the safety monitoring function of the processing platform in order to determine compliance of the processing platform with operational requirements, configuring the safety monitoring function of the processing platform utilizing one or more sets of safety monitoring configuration data, initializing and configuring a security monitoring function of the processing platform, and initializing and configuring one or more security functions.


