SoC Isolation Control Architecture for Privilege Escalation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security architectures for system-on-chip (SoC) information handling systems face challenges in providing effective protection and isolation against malicious attacks, particularly due to vulnerabilities in privilege-based isolation schemes and limitations of dedicated secure enclave subsystems, which can be compromised by privilege-escalation attacks and lack dynamic runtime control.

Innovation Solution

A dynamic runtime isolation architecture is implemented using a dedicated SoC control point entity that creates programmable isolation barriers around each execution domain through a two-way control channel, independent from execution domain processors and software, allowing for dynamic reconfiguration and monitoring of access and isolation constraints.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If privilege-based isolation schemes are used to protect processing subsystems, then isolation between software entities is achieved, but the system becomes vulnerable to privilege-escalation attacks that can compromise the entire security model

Engineering Contradiction:
Improveisolation securityVSAvoidprivilege-escalation attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a dedicated secure enclave subsystem as an intermediary control point between processing subsystems and shared resources. This enclave acts as a mediator that enforces isolation policies independently of processor privilege mechanisms, preventing privilege-escalation attacks from compromising the security model. The enclave intercepts and controls access to shared interconnection infrastructure, ensuring that even compromised high-privilege software cannot bypass isolation boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the system control into separate functional units: execution domain processors, a dedicated secure enclave subsystem, and filtering hardware. This segmentation isolates the security control functions from the potentially compromised processing subsystems. The secure enclave operates as a separate control point that can enforce isolation policies without being affected by privilege escalation within any single processing subsystem.

Inventive Principle:
Principle #1Segmentation

2Reliability

If dedicated secure enclave subsystems are implemented to provide boot control point and address space control, then protection during boot is achieved, but dynamic runtime isolation control and protection of physical interconnection infrastructure are not provided

Engineering Contradiction:
Improveboot time protectionVSAvoiddynamic runtime control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent extends the secure enclave's isolation control capabilities from static boot-time operations to dynamic runtime operations. The filtering hardware within the enclave can be reconfigured during system operation to adapt isolation policies based on runtime conditions. This allows the system to dynamically respond to security threats and modify access controls without requiring system reboot, enhancing both runtime protection and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The dedicated secure enclave subsystem is designed to perform multiple functions: it provides boot control point operations, address space control, and dynamic runtime isolation control. The filtering hardware can operate at different stages of system operation and can control access to various types of shared resources including interconnection infrastructure, making the enclave a universal security control mechanism throughout the system lifecycle.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If filtering hardware is used to prevent unauthorized access to shared resources, then isolation between address space targets is achieved, but the physical interconnection infrastructure remains unprotected and accessible to malicious code

Engineering Contradiction:
Improveaddress space isolationVSAvoidinterconnection infrastructure exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent positions the secure enclave with filtering hardware as an intermediary control point in the data path between processing subsystems and shared resources. This intermediary intercepts access requests before they reach the physical interconnection infrastructure, examining and controlling access based on isolation policies. By placing the filter in this intermediate position, the system protects both address space targets and the underlying interconnection infrastructure from unauthorized access and malicious code.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240020150A1System on Chip Isolation Control Architecture
Publication Date: 2024.01.18 NXP USA INC
  • US20240020150A1 patent drawing
  • US20240020150A1 patent drawing
  • US20240020150A1 patent drawing

AI summary

A method and apparatus are disclosed for a multi-processor system on a chip which includes at least a first execution domain processor that is configured to run a first execution domain by accessing one or more system-on-chip resources; a first control point processor that is physically and programmatically independent from the first execution domain processor and that is configured to generate a first runtime isolation control data stream for controlling access to the one or more system-on-chip resources by the first execution domain; and an access control circuit connected between the first execution domain processor and the one or more system-on-chip resources and configured to provide a dynamic runtime isolation barrier in response to the first runtime isolation control data stream, thereby controlling access to the one or more system-on-chip resources by the first execution domain.