SoC Data Security Appliance FPGA Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Software-based data security mechanisms are increasingly vulnerable to targeted attacks due to rising complexity and connectivity, which can compromise data security even when kernel-level access is gained within networks, especially in systems like high assurance guards (HAGs).

Innovation Solution

A system-on-chip data security appliance (SoC-DSA) is introduced, which encloses data security mechanisms within a single chip's physical boundary, using a field-programmable gate array (FPGA) to implement isolation and access control that is not visible or alterable by software, ensuring continued security even in the presence of software exploitation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based data security mechanisms are used, then data security can be implemented, but vulnerability to targeted attacks increases due to software complexity and connectivity

Engineering Contradiction:
Improvedata securityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware-based security mechanisms implemented in FPGA and ASIC circuits. This substitution moves security functions from the vulnerable software layer to the hardware layer, where isolation and access control are enforced by physical circuitry rather than executable code, thereby eliminating vulnerabilities associated with software complexity and connectivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent segments the system into distinct hardware components with enforced isolation boundaries. The FPGA contains isolated security domains with dedicated logic blocks, memory blocks, and interconnect structures that physically separate different security contexts. This segmentation ensures that even if one domain is compromised, the hardware isolation prevents propagation to other domains.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware-based security mechanisms are implemented in FPGA, then isolation and access control become invisible and unalterable by software, but device complexity increases

Engineering Contradiction:
Improvesecurity against software exploitationVSAvoidhardware architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal hardware security architecture in FPGA that can enforce multiple isolation and access control policies simultaneously through a single unified structure. The FPGA fabric contains generic logic blocks, memory blocks, and interconnect resources that can be configured to implement various security domains and policies, eliminating the need for separate hardware circuits for each security function and thereby managing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary hardware layer between the software operating system and the physical data paths. This intermediary consists of FPGA logic blocks and interconnect structures that mediate all data flow and access requests, enforcing security policies at the hardware level without requiring software intervention. This intermediary shields the software from hardware complexity while maintaining strong security guarantees.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data security mechanisms are enclosed within a single chip's physical boundary, then protection against software exploitation is enhanced, but manufacturing and integration become more difficult

Engineering Contradiction:
Improveprotection boundaryVSAvoidsingle-chip integration
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges multiple security functions, logic blocks, memory blocks, and interconnect structures into a single integrated FPGA chip. This consolidation creates a self-contained security appliance where all security-critical components reside within one physical boundary, eliminating the need for multiple discrete components and reducing attack surfaces while maintaining manufacturing feasibility through standard FPGA fabrication processes.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10616344B2System-on-chip data security appliance encryption device and methods of operating the same
Publication Date: 2020.04.07 WEB SENSING LLC
  • US10616344B2 patent drawing
  • US10616344B2 patent drawing
  • US10616344B2 patent drawing

AI summary

System-on-chip data security appliance (“SoC-DSA”) and methods of operating the same. In one embodiment, the SoC-DSA includes data security mechanisms enclosed within a protected boundary of a single chip. In some embodiments, isolation and access control features are hidden within an on-chip field-programmable gate array (“FPGA”). The isolation and access control features can be implemented such that they are not visible to or alterable by software executing on the processing cores of the SoC-DSA, which provides for continued data security even in the presence of software exploitation, such as a malicious implant, that otherwise compromises data security in software-only systems. The SoC-DSA can be used to enhance data security in existing data security devices and protocols, such as high assurance guards (“HAG”) and can be used to create new types of security devices, such as devices enforce alternative human data interactions (“HDI”) models.