IP Library Granted Patent US 10,083,305
Granted Patent B2
US 10,083,305 · App. 14/773,679 · Granted Sep 25, 2018

Method and system providing mutli-level security to gate level information flow

Inventors: Ryan Kastner (La Jolla, CA); Jason Oberg (La Jolla, CA); Wei Hu (La Jolla, CA); Timothy Sherwood (Santa Barbara, CA); Mohit Tiwari (Austin, TX)
Assignee: The Regents of the University of California
G06F21/60G06F2221/2113
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,083,305
App. No.
14/773,679
Granted
Sep 25, 2018
Kind
B2
Abstract

A preferred method for providing multi-level security to a gate level information flow receives or specifies a security lattice having more than two security levels. The security lattice defines how security levels relate to each other. A hardware design implementing information flows including flows having security levels specified by the security lattice is received. Logic is created for testing the hardware design in view of the security lattice. A logic function is created based upon the hardware design and the logic for testing to implement the security lattice. Another method receives a hardware design in a hardware description language. At least a portion of the hardware design is synthesized to gate level primitives. Functional component tracking logic supporting more than two-security levels is built from the gate level primitives. Functional components in the hardware design are simulated with the functional component tracking logic.

Claims (16)

1. A method for providing multi-level security to a gate level information flow, the method comprising:

receiving or specifying a security lattice having more than two security levels, wherein the security lattice defines how security levels relate to each other by defining permitted communication channels between security levels and permitted information flow directions between the security levels;

receiving a hardware design implementing information flows including flows having security levels specified by the security lattice;

creating logic for testing the hardware design in view of the security lattice, wherein at least a portion of the hardware design is synthesized into primitive gate level hardware components and the logic adds more than two security level tracking logic to the gate level hardware components to test for violations of the permitted communication channels and the permitted information flow directions; and

outputting a logic function based upon the hardware design and the logic for testing to implement the security lattice.

2. The method of claim 1 , further comprising converting the logic function to a hardware design specification.

3. The method of claim 1 , wherein the hardware design is in a hardware description language.

4. The method of claim 1 , wherein said creating comprises building functional components of the hardware design from gate-level GLIFT (gate level information flow tracking) components to create complex GLIFT functional components and said outputting replaces portions of the hardware design with the complex GLIFT functional components.

5. The method of claim 1 , wherein said receiving or specifying a security lattice comprises converting a two-level GLIFT label propagation logic to a more than two level security label propagation logic.

6. The method of claim 1 , wherein

said receiving receives the hardware design in a hardware description language;

said creating logic comprises building functional component tracking logic;

and further comprising simulating functional components in the hardware design with the functional component tracking logic.

7. The method of claim 6 , further comprising testing an information flow labeled with one of the security levels for leaking to a lower classified security level area of the hardware design.

8. The method of claim 7 , wherein said testing accounts for values that can be taken by the information flow in addition to the security level of the information flow.

9. The method of claim 7 , wherein said simulating comprises gate level information flow tracking and an output of the flow tracking is bounded to the most restrictive security class whose data has an effect on the output.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2026
From: CYCUITY, INC.
To: ARTERIS, INC.
Reel/Frame 074830/0617 →
MERGER Recorded Apr 9, 2026
From: ARTERIS, INC.; CABERNET MERGER SUB I, INC.; ARTERIS SECURITY, LLC
To: ARTERIS, INC.
Reel/Frame 074318/0437 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 4, 2016
From: TIWARI, MOHIT
To: THE REGENTS OF THE UNIVERSITY OF CALIFORNIA
Reel/Frame 037896/0389 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2015
From: KASTNER, RYAN; OBERG, JASON; HU, WEI; SHERWOOD, TIMOTHY
To: THE REGENTS OF THE UNIVERSITY OF CALIFORNIA
Reel/Frame 036535/0151 →
Continuity (2)
Provisional Application 61787941 · Mar 15, 2013
Related Publication 20160026801A1 · Jan 28, 2016