Adaptive DBD Hardware Firewall for SoC Wake-Up Optimization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional hardware firewalls employ fixed access control mechanisms that are undesirable in complex applications requiring different operating modes or specific wake-up requirements, as they either allow unrestricted access or deny all access indiscriminately, leading to inefficient wake-up times and security vulnerabilities.

Innovation Solution

The implementation of adaptive Deny-By-Default (DBD) access controls in hardware firewalls, which create 'tunnels' for specific processing cores or bus masters to access microchip components during reset or low-power events, while restricting others, allowing for dynamic policy changes based on the microchip's lifecycle stage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If a fixed access control mechanism (allow all or deny all) is applied during reset, then the hardware firewall is simple to implement, but wake-up time increases and security is compromised

Engineering Contradiction:
Improveease of implementationVSAvoidwake-up time
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The access control mechanism transitions from static (fixed allow/deny policies) to dynamic (adaptive policies that change based on system state). The hardware firewall now adapts its access control behavior based on the reset state, allowing selective access during initialization while maintaining security during normal operation, thereby reducing wake-up time without compromising security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the access control parameter from fixed binary states (allow all/deny all) to adaptive states that vary based on system lifecycle. By introducing state-dependent access control, the system can optimize wake-up performance during reset while maintaining security posture during normal operation, resolving the contradiction between implementation simplicity and performance.

Inventive Principle:
Principle #35Parameter changes

2Ease of manufacture

If a fixed access control mechanism is applied, then the hardware firewall is easy to program, but it cannot support complex operating modes or specific wakeup requirements

Engineering Contradiction:
Improveease of programmingVSAvoidadaptability to operating modes
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The access control policy evolves from static to dynamic, enabling the hardware firewall to adapt to different operating modes and wakeup requirements. The system can now be programmed with adaptive policies that automatically adjust based on system state, maintaining ease of programming while significantly improving adaptability to complex operating scenarios.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The hardware firewall incorporates feedback mechanisms that monitor system state and adjust access control policies accordingly. This feedback-driven adaptation allows the system to automatically respond to different operating modes and wakeup requirements without complex reprogramming, resolving the contradiction between programming simplicity and operational adaptability.

Inventive Principle:
Principle #23Feedback

3Loss of time

If unrestricted access is applied during reset, then wake-up time is reduced, but security vulnerabilities increase

Engineering Contradiction:
Improvewake-up timeVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The access control mechanism applies different quality levels of access to different system regions during reset. Instead of uniform unrestricted access, the system provides selective access to specific memory spaces and peripherals needed for initialization, while maintaining restricted access to security-critical regions. This local differentiation reduces wake-up time for necessary components without exposing security vulnerabilities.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The access control policy dynamically adjusts based on system state, transitioning from restricted to more permissive access only when necessary and safe. During reset, the system applies adaptive policies that allow necessary access while maintaining security posture, thereby reducing wake-up time without introducing security vulnerabilities through unrestricted access.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12126595B2Hardware firewalls with adaptive deny-by-default (DBD) access control
Publication Date: 2024.10.22 NXP USA INC
  • US12126595B2 patent drawing
  • US12126595B2 patent drawing

AI summary

In an embodiment, a System-on-Chip (SoC) may include: a plurality of core domains, and a memory coupled to the plurality of core domains through a hardware firewall, wherein the hardware firewall is configured to enforce an adaptive Deny-By-Default (DBD) access policy in response to an event. In another embodiment, a circuit, may include: an access control policy generator configured to produce an adaptive DBD policy, and a hardware firewall coupled to the access control policy generator, the hardware firewall configured to enforce the adaptive DBD policy. In yet another embodiment, a method may include: storing an indication of a first DBD configuration state, the first DBD configuration state usable to enforce a first DBD access control policy, and changing the stored indication to a second DBD configuration state, the second DBD configuration state usable to enforce a second DBD access control policy.