Storage Controller Secure Partitioning via Range Registers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current integrated circuits with storage controllers lack efficient mechanisms to securely partition storage devices into secure and non-secure areas, leading to potential unauthorized access and data breaches when operating in mixed security modes.
Innovation Solution
The implementation of storage controllers with command-chain-driven bus-mastering capabilities, utilizing range registers and direction bits to logically partition storage devices into secure and non-secure partitions, and enforcing security modes through bit signaling on the bus to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If storage devices are accessed in mixed security modes without partitioning, then operational flexibility is improved, but security is worsened due to potential unauthorized access
Solution Approach 1:
The patent divides the storage device into distinct secure and non-secure partitions using range registers and direction bits. This segmentation allows different security modes to coexist by physically separating accessible storage regions, thereby maintaining operational flexibility while preventing unauthorized access to secure areas.
Solution Approach 2:
The patent introduces a security mode indicator and range registers as intermediary mechanisms that mediate between the processor and storage device. These intermediaries enforce security policies by controlling which partitions are accessible based on the current security mode, thus maintaining both flexibility and security.
2Reliability
If storage devices are partitioned into secure and non-secure areas, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent applies local quality by implementing security attributes at the partition level rather than requiring system-wide complexity. Each partition is tagged with security attributes that determine accessibility, allowing the controller to enforce security through simple attribute checks rather than complex authentication protocols.
Solution Approach 2:
The patent changes the parameter of storage accessibility by using direction bits and range registers to dynamically control which partitions are accessible. This parameter-based approach simplifies the controller logic compared to implementing complex access control lists or permission systems.
3Reliability
If security modes are enforced through bit signaling, then unauthorized access is prevented, but processing overhead is increased
Solution Approach 1:
The patent performs preliminary action by pre-configuring range registers and security attributes during system initialization or partition creation. This allows the controller to make access decisions based on pre-computed ranges and attributes rather than performing complex security evaluations during each access operation, thereby reducing processing overhead.
Solution Approach 2:
The patent implements self-service by enabling the storage controller to automatically enforce security policies through hardware-based range checking and mode detection. This eliminates the need for software-based access control mechanisms, reducing processing overhead while maintaining robust security enforcement.
Data Source
AI summary
A storage controller includes a command pointer register. The command pointer register points to a chain of commands in memory, and also includes a security status field to indicate a security status of the first command in the command chain. Each command in the command chain may also include a security status field that indicates the security status of the following command in the chain.


