Address-Space Partitioning Mechanism for Secure Multi-Processor Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory management systems in computing systems face challenges in efficiently partitioning and allocating memory resources among processors while maintaining security and isolation, particularly in systems with multiple virtual machines and peripheral devices, leading to increased hardware complexity and cost.
Innovation Solution
A system-on-a-chip (SoC) world controller manages memory partitioning and allocation by creating mutually distrusting domains using a memory partitioning mechanism, which includes a trusted off-processor entity to control physical address space partitioning, reducing the need for additional System MMUs and enhancing memory management protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional memory management systems use separate System MMUs for each processor to ensure security and isolation, then system security and isolation are improved, but hardware complexity and cost increase
Solution Approach 1:
The patent merges the memory management functions previously handled by separate System MMUs into a unified memory management mechanism. The first processor's memory management unit (MMU) is extended to handle memory management for multiple processors, eliminating the need for dedicated System MMUs on each processor and reducing hardware complexity while maintaining security and isolation through software-based memory partitioning and allocation mechanisms
2Reliability
If multiple System MMUs are deployed for each processor to manage memory isolation, then memory isolation between processors is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal memory management approach where the first processor's MMU serves multiple functions including memory management for itself and other processors. The system uses a unified page table structure that can be configured to provide memory isolation for multiple processors, allowing a single MMU instance to perform what would traditionally require multiple dedicated MMUs, thereby reducing device complexity while maintaining memory isolation capabilities
3Productivity
If a trusted off-processor entity is introduced to control physical address space partitioning, then memory management efficiency is improved, but system architecture complexity increases
Solution Approach 1:
The patent introduces a trusted off-processor entity as an intermediary between processors and the memory management system. This entity receives memory management requests from processors, translates them into appropriate memory operations, and coordinates access to physical address space. The intermediary handles complex tasks like memory partitioning and allocation centrally, improving memory management efficiency while containing architecture complexity in a dedicated management component rather than distributing it across multiple processors
Data Source
AI summary
Certain aspects provide a technique for partitioning a memory associated with one or more application processors (AP). For example, a first AP may partition a memory associated with a second AP to create multiple memory regions. The first AP may then allocate different memory regions associated with the second AP to different processing domains associated with the second AP or other APs for different tasks.


