Hierarchical Secure Master–Guest Endpoint Firewall for Core Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security systems fail to maintain secure data integrity when a secure core is compromised, as they cannot distinguish between compromised and non-compromised requestors, leading to the exposure of secure data.
Innovation Solution
Implementing a security firewall with a hierarchical structure that includes Secure Master (SM), Secure Guest (SG), and Non-Secure (NS) levels, allowing distinct secure regions and access control based on security identities, with options for downgrading non-secure access if necessary.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single secure core is used to protect secure data, then security protection is provided, but if the secure core is compromised all secure data becomes vulnerable as the compromised core retains access rights
Solution Approach 1:
The patent segments the previously monolithic secure core into multiple secure cores with different security clearances (secure master and secure guest). This segmentation allows the system to maintain security even if one core is compromised, as not all cores have access to all secure data regions. The secure master core has full access while secure guest cores have restricted access to specific secure regions.
2Device complexity
If access control is based on a single security level, then implementation is simple, but the system cannot distinguish between compromised and non-compromised secure requestors
Solution Approach 1:
The patent introduces an additional dimension to security identification by implementing a hierarchical security model with multiple levels (secure master and secure guest) rather than a single security level. This dimensional expansion enables the system to differentiate between various types of secure requestors based on their security clearance level, allowing precise identification of compromised versus non-compromised cores.
3Ease of operation
If all secure cores have equal access rights to secure data, then access control is straightforward, but compromise of any core threatens the entire secure data space
Solution Approach 1:
The patent applies local quality by assigning different access rights to different secure cores based on their security clearance level. Secure master cores have full access to all secure regions, while secure guest cores have restricted access to specific secure regions. This differentiated access control maintains operational simplicity while enhancing security reliability through localized access restrictions.
Data Source
AI summary
Disclosed embodiments relate to a security firewall having a security hierarchy including: secure master (SM); secure guest (SG); and non-secure (NS). There is one secure master and n secure guests. The firewall includes one secure region for secure master and one secure region for secure guests. The SM region only allows access from the secure master and the SG region allows accesses from any secure transaction. Finally, the non-secure region can be implemented two ways. In a first option, non-secure regions may be accessed only upon non-secure transactions. In a second option, non-secure regions may be accessed any processing core. In this second option, the access is downgraded to a non-secure access if the security identity is secure master or secure guest. If the two security levels are not needed the secure master can unlock the SM region to allow any secure guest access to the SM region.


