Hardware Security Class Matrix for Zero Trust SoC

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure computing environments are vulnerable to attacks due to software-based security measures that rely on detection after penetration, lacking a penetration-independent security solution and failing to enforce Zero Trust principles consistently across all instructions and transactions.

Innovation Solution

A hardware-based security architecture for Systems on Chip (SoC) that enforces Zero Trust by assigning a security class to each memory block, using a classification matrix to manage interactions between security classes, and ensuring only authorized devices can access data, preventing unauthorized access and data corruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based security measures are used to protect data and code, then security coverage can be extended across the system, but the security becomes vulnerable to attacks that exploit software vulnerabilities and loopholes

Engineering Contradiction:
Improvesecurity coverageVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware-based security mechanisms. Specifically, it introduces hardware security classifications and a security class matrix that operate at the hardware level (in memory controllers and processing elements) to enforce security policies, thereby eliminating vulnerabilities associated with software-based security while maintaining comprehensive security coverage across the computing system.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Difficulty of detecting and measuring

If firewalls and monitoring systems are deployed to detect and prevent attacks, then security detection capability is improved, but security breaches are only closed after detection causing damage to occur

Engineering Contradiction:
Improveattack detection capabilityVSAvoidresponse time
Core Design Contradiction:
Difficulty of detecting and measuringVSLoss of time

Solution Approach 1:

The patent implements preliminary security actions by embedding security classifications and access control rules directly into the hardware architecture before any attacks can occur. The security class matrix pre-defines which security classes can access which memory blocks, and the memory controller automatically enforces these rules on every memory access operation, preventing breaches before they can cause damage rather than detecting them after the fact.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If continuous protection of sensitive data in memory is implemented through software mechanisms, then data security during operations is improved, but the protection system itself becomes vulnerable to malicious penetrators exploiting software vulnerabilities

Engineering Contradiction:
Improvedata protection during operationsVSAvoidexposure to software-based attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based continuous protection mechanisms with hardware-based security enforcement. The memory controller, implemented in hardware, continuously monitors and controls all memory access operations based on security classifications attached to data and code. This hardware-level enforcement cannot be exploited by software-based attacks or malicious penetrators, while maintaining continuous protection of sensitive data throughout all system operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If hardware-based security classifications and matrices are implemented to enforce Zero Trust, then penetration-independent security is achieved, but device complexity increases

Engineering Contradiction:
Improvepenetration-independent securityVSAvoidhardware security architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functionality directly into existing memory controller and processing element hardware components rather than adding separate security subsystems. Security classifications are integrated into memory management structures, and the security class matrix is embedded within the memory controller's address translation and access control logic. This merging approach achieves penetration-independent Zero Trust security while minimizing increases in overall device complexity by reusing existing hardware infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20250021495A1Architecture, system and methods thereof for secure computing using hardware security classifications
Publication Date: 2025.01.16 LEMPEL MORDKHAI
  • US20250021495A1 patent drawing
  • US20250021495A1 patent drawing
  • US20250021495A1 patent drawing

AI summary

A system for secured computing comprises: an interconnect; a processing element communicatively connected to the interconnect; and a memory controller communicatively connected to the interconnect and to a memory; wherein access of a memory block by the memory controller to and from the interconnect is accompanied by a security class of a plurality of security classes; wherein each memory block is associated with a security class assigned to the content stored in the memory block from amongst a plurality of security classes; wherein the associated security class of each memory block travels in the system together with the content of the associated memory block; wherein the memory controller employs at least one matrix; and wherein the at least one matrix defines interactions between the security classes of memory blocks of content as the content of the memory blocks which are being handled by at least the memory controller.