Secure Partitioning Architecture for Software-Hardware Resource Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing reconfigurable systems face challenges in partitioning processing operations for high security levels, as they are limited by software solutions and require the integration of hardware properties, necessitating an architecture that combines software and hardware functionalities for flexible and robust partitioning.

Innovation Solution

A method and architecture that partitions both the main software platform and secondary hardware platform, using a hypervisor for intra-platform partitioning and secure communication mechanisms, with specific drivers ensuring encrypted connections between partitions and processing units, allowing for flexible and secure distribution of processing operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software solutions are used for partitioning, then flexibility is improved, but security and robustness deteriorate

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system divides the architecture into multiple partitions (first partition, second partition, third partition) with distinct security levels. Each partition can be independently configured and managed, allowing flexible software-based partitioning while maintaining hardware-enforced security boundaries. The partitioning mechanism enables different security policies to be applied to different segments of the system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A partitioning mechanism acts as an intermediary layer between software applications and hardware resources. This mechanism provides secure communication channels and controlled access between partitions, enabling flexible software management while maintaining hardware-level security enforcement through the intermediary partitioning layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware properties are integrated for security, then security and robustness are improved, but flexibility and reconfigurability deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The partitioning mechanism provides dynamic reconfiguration capabilities, allowing the system to change partition assignments, security policies, and resource allocations at runtime. This enables the hardware security features to be dynamically adjusted to meet different security requirements while maintaining flexibility in system configuration and operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The partitioning mechanism serves multiple functions simultaneously: it provides hardware-enforced security boundaries, enables flexible software partitioning, manages resource allocation, and controls communication between different security domains. This multi-functional approach allows a single mechanism to deliver both security robustness and system flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If compartmentalization is implemented for high security, then security assessment compliance is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity assessment complianceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements compartmentalization by dividing the architecture into distinct partitions with defined security boundaries. This segmentation approach satisfies security assessment requirements for isolation while managing complexity through structured organization of security domains and controlled inter-partition communication mechanisms.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3026555B1Method for managing an architecture and associated architecture
Publication Date: 2024.02.21 THALES SA
  • EP3026555B1 patent drawingFigure 1~2

AI summary

The invention relates to a method for managing an architecture (10), the architecture (10) comprising: - a main platform (12) comprising a plurality of software execution partitions (16), and - at least one secondary platform (14), the method comprising at least one step of: - associating each partition (16) of the main platform (12) with at least one processing unit (20) per installation, for each partition (16) and each processing unit (20), of a driver (24) specific to the partition (16) considered, the driver (24) ensuring a secure link between the partition (16) considered and the processing unit(s) (20) to which the partition is associated.