SoC Isolation Control Architecture for Privilege Escalation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security architectures for system-on-chip (SoC) information handling systems face challenges in providing effective protection and isolation against malicious attacks, particularly due to vulnerabilities in privilege-based isolation schemes and limitations of dedicated secure enclave subsystems, which can be compromised by privilege-escalation attacks and lack dynamic runtime control.
Innovation Solution
A dynamic runtime isolation architecture is implemented using a dedicated SoC control point entity that creates programmable isolation barriers around each execution domain through a two-way control channel, independent from execution domain processors and software, allowing for dynamic reconfiguration and monitoring of access and isolation constraints.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If privilege-based isolation schemes are used to protect processing subsystems, then isolation between software entities is achieved, but the system becomes vulnerable to privilege-escalation attacks that can compromise the entire security model
Solution Approach 1:
The patent introduces a dedicated secure enclave subsystem as an intermediary control point between processing subsystems and shared resources. This enclave acts as a mediator that enforces isolation policies independently of processor privilege mechanisms, preventing privilege-escalation attacks from compromising the security model. The enclave intercepts and controls access to shared interconnection infrastructure, ensuring that even compromised high-privilege software cannot bypass isolation boundaries.
Solution Approach 2:
The patent segments the system control into separate functional units: execution domain processors, a dedicated secure enclave subsystem, and filtering hardware. This segmentation isolates the security control functions from the potentially compromised processing subsystems. The secure enclave operates as a separate control point that can enforce isolation policies without being affected by privilege escalation within any single processing subsystem.
2Reliability
If dedicated secure enclave subsystems are implemented to provide boot control point and address space control, then protection during boot is achieved, but dynamic runtime isolation control and protection of physical interconnection infrastructure are not provided
Solution Approach 1:
The patent extends the secure enclave's isolation control capabilities from static boot-time operations to dynamic runtime operations. The filtering hardware within the enclave can be reconfigured during system operation to adapt isolation policies based on runtime conditions. This allows the system to dynamically respond to security threats and modify access controls without requiring system reboot, enhancing both runtime protection and adaptability.
Solution Approach 2:
The dedicated secure enclave subsystem is designed to perform multiple functions: it provides boot control point operations, address space control, and dynamic runtime isolation control. The filtering hardware can operate at different stages of system operation and can control access to various types of shared resources including interconnection infrastructure, making the enclave a universal security control mechanism throughout the system lifecycle.
3Reliability
If filtering hardware is used to prevent unauthorized access to shared resources, then isolation between address space targets is achieved, but the physical interconnection infrastructure remains unprotected and accessible to malicious code
Solution Approach 1:
The patent positions the secure enclave with filtering hardware as an intermediary control point in the data path between processing subsystems and shared resources. This intermediary intercepts access requests before they reach the physical interconnection infrastructure, examining and controlling access based on isolation policies. By placing the filter in this intermediate position, the system protects both address space targets and the underlying interconnection infrastructure from unauthorized access and malicious code.
Data Source
AI summary
A method and apparatus are disclosed for a multi-processor system on a chip which includes at least a first execution domain processor that is configured to run a first execution domain by accessing one or more system-on-chip resources; a first control point processor that is physically and programmatically independent from the first execution domain processor and that is configured to generate a first runtime isolation control data stream for controlling access to the one or more system-on-chip resources by the first execution domain; and an access control circuit connected between the first execution domain processor and the one or more system-on-chip resources and configured to provide a dynamic runtime isolation barrier in response to the first runtime isolation control data stream, thereby controlling access to the one or more system-on-chip resources by the first execution domain.


