Hardware Security Class Matrix for Zero Trust SoC
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure computing environments are vulnerable to attacks due to software-based security measures that rely on detection after penetration, lacking a penetration-independent security solution and failing to enforce Zero Trust principles consistently across all instructions and transactions.
Innovation Solution
A hardware-based security architecture for Systems on Chip (SoC) that enforces Zero Trust by assigning a security class to each memory block, using a classification matrix to manage interactions between security classes, and ensuring only authorized devices can access data, preventing unauthorized access and data corruption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based security measures are used to protect data and code, then security coverage can be extended across the system, but the security becomes vulnerable to attacks that exploit software vulnerabilities and loopholes
Solution Approach 1:
The patent replaces software-based security mechanisms with hardware-based security mechanisms. Specifically, it introduces hardware security classifications and a security class matrix that operate at the hardware level (in memory controllers and processing elements) to enforce security policies, thereby eliminating vulnerabilities associated with software-based security while maintaining comprehensive security coverage across the computing system.
2Difficulty of detecting and measuring
If firewalls and monitoring systems are deployed to detect and prevent attacks, then security detection capability is improved, but security breaches are only closed after detection causing damage to occur
Solution Approach 1:
The patent implements preliminary security actions by embedding security classifications and access control rules directly into the hardware architecture before any attacks can occur. The security class matrix pre-defines which security classes can access which memory blocks, and the memory controller automatically enforces these rules on every memory access operation, preventing breaches before they can cause damage rather than detecting them after the fact.
3Reliability
If continuous protection of sensitive data in memory is implemented through software mechanisms, then data security during operations is improved, but the protection system itself becomes vulnerable to malicious penetrators exploiting software vulnerabilities
Solution Approach 1:
The patent replaces software-based continuous protection mechanisms with hardware-based security enforcement. The memory controller, implemented in hardware, continuously monitors and controls all memory access operations based on security classifications attached to data and code. This hardware-level enforcement cannot be exploited by software-based attacks or malicious penetrators, while maintaining continuous protection of sensitive data throughout all system operations.
4Reliability
If hardware-based security classifications and matrices are implemented to enforce Zero Trust, then penetration-independent security is achieved, but device complexity increases
Solution Approach 1:
The patent merges security functionality directly into existing memory controller and processing element hardware components rather than adding separate security subsystems. Security classifications are integrated into memory management structures, and the security class matrix is embedded within the memory controller's address translation and access control logic. This merging approach achieves penetration-independent Zero Trust security while minimizing increases in overall device complexity by reusing existing hardware infrastructure.
Data Source
AI summary
A system for secured computing comprises: an interconnect; a processing element communicatively connected to the interconnect; and a memory controller communicatively connected to the interconnect and to a memory; wherein access of a memory block by the memory controller to and from the interconnect is accompanied by a security class of a plurality of security classes; wherein each memory block is associated with a security class assigned to the content stored in the memory block from amongst a plurality of security classes; wherein the associated security class of each memory block travels in the system together with the content of the associated memory block; wherein the memory controller employs at least one matrix; and wherein the at least one matrix defines interactions between the security classes of memory blocks of content as the content of the memory blocks which are being handled by at least the memory controller.


