Secure Processor Collaboration via Memory Sandboxing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-processor systems, ensuring secure collaboration between processors is challenging, especially when one processor needs to monitor or access data from a secure processor, as conventional security measures can be compromised by external influences and unauthorized access.
Innovation Solution
A main processor controls the memory space to establish a semi-isolated relationship between a secure and an unsecure processor, authenticating boot code, operating systems, and content, and managing access to shared memory sandboxes to prevent unauthorized data access while allowing secure data sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a processor enters a secure mode where no externally-initiated data access requests are serviced, then security is improved, but the main processor cannot access data for monitoring and management functions
Solution Approach 1:
The patent segments the memory space into multiple sandboxes, each accessible only to specific processors. The secure processor's sandbox is controlled by the main processor, allowing selective access. This segmentation enables the secure processor to maintain security while permitting monitored access by the main processor to specific data regions.
Solution Approach 2:
The patent introduces an intermediary memory structure (sandbox) that mediates between the secure processor and the main processor. The sandbox acts as a controlled interface where the main processor can access secure data under defined conditions, resolving the conflict between security isolation and management oversight.
2Reliability
If conventional security measures are used in multi-processor systems, then data protection is improved, but the system becomes vulnerable to hacking, viruses, and unauthorized access from shared network resources
Solution Approach 1:
The patent applies preliminary anti-action by authenticating boot code, operating systems, and content before execution. This pre-authentication prevents malicious code from compromising the system, addressing external threats before they can cause harm. The secure boot process ensures that only authorized software runs on the processor.
Solution Approach 2:
The patent divides the memory space into isolated sandboxes that prevent external threats from propagating across the entire system. Each processor has controlled access to specific memory regions, limiting the impact of hacking or viruses to isolated segments rather than the whole system.
3Reliability
If a secure processor completely isolates its data from other processors, then security is improved, but collaborative processing and task management between processors deteriorates
Solution Approach 1:
The patent segments memory into sandboxes with controlled access permissions. The secure processor's sandbox is managed by the main processor, allowing selective sharing of specific data regions while maintaining overall security. This enables collaborative processing within defined boundaries rather than complete isolation.
Solution Approach 2:
The patent implements dynamic access control where the main processor can adjust which data regions in the secure processor's sandbox are accessible. This dynamic management allows the system to adapt collaboration levels based on security requirements, enabling versatile inter-processor communication while maintaining security.
Data Source
AI summary
In a multi-processor system including a plurality of processors capable of being operatively coupled to the main memory and each processor including an associated local memory, and at least one main processor operable to control access by the processors to data within the main memory and within the processors, methods and apparatus provide for: entering a secure mode of operation within at least one of the processors in which no requests initiated by others of the processors for data transfers into or out of the at least one processor are serviced, but such transfers initiated by the at least one processor are serviced subject to the access controlled by the main processing unit; and using the main processing unit to exclude access to data associated with at least one further processor by others of the processors except for the at least one processor.


