Bus Master Domain Security via External Control Logic

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complexity and security vulnerabilities arise in processors that support both secure and non-secure domains, making it difficult to share data between domains without compromising security, especially when a processor is fixed in one security domain and lacks the ability to transition between them.

Innovation Solution

A data processing apparatus with a bus master device that operates in a fixed security domain, using external signals to determine its domain and generate appropriate domain security signals for access requests, allowing secure processes to label data as non-secure for sharing with non-secure processes, thereby enabling secure data access without internal domain switching capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a processor supports both secure and non-secure domains with internal domain switching capabilities, then data sharing flexibility is improved, but device complexity and security vulnerabilities increase

Engineering Contradiction:
Improvedata sharing flexibilityVSAvoidprocessor complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the domain switching capability from the processor and places it externally. The bus master device operates in a fixed security domain determined by an external signal, while the domain control logic externally generates domain specifying signals. This separates the security domain determination function from the processor itself, reducing internal complexity while maintaining the ability to share data between secure and non-secure domains.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary domain control logic that sits between the bus master device and the memory bus. This intermediary generates domain specifying signals based on external inputs and memory address information, acting as a mediator that determines security domain attributes without requiring the bus master to have internal switching capabilities. The intermediary handles the complexity of domain management externally.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a processor is fixed in one security domain, then security is improved by preventing malicious domain switching, but data sharing capability with other domains is reduced

Engineering Contradiction:
ImprovesecurityVSAvoiddata sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the bus master device universal by enabling it to operate in any security domain (secure or non-secure) depending on the external domain specifying signal. While the bus master itself is fixed in one domain at any given time, the system as a whole can configure the bus master to operate in different domains through external control signals, maintaining both security through fixed operation and adaptability through external configuration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent changes the security domain parameter of the bus master device externally through domain specifying signals. Instead of the processor internally switching between secure and non-secure domains, the external domain control logic modifies the domain parameter by generating appropriate signals that cause the bus master to operate in the required security domain, enabling flexible data sharing while maintaining security through external control.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If domain control logic selectively generates non-secure domain security signals for data sharing, then data sharing between domains is enabled, but device complexity increases

Engineering Contradiction:
Improvedata sharing between domainsVSAvoiddomain control logic complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by making the domain control logic address-dependent in its behavior. The domain control logic examines the memory address specified in the access request and selectively generates non-secure domain security signals only for specific address ranges that are intended for sharing. This targeted approach allows data sharing for specific memory regions without requiring the entire system to handle all possible domain transition scenarios, reducing overall complexity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent applies partial action by having the domain control logic generate non-secure domain security signals only when necessary, specifically when the memory address indicates a region intended for sharing between secure and non-secure domains. Rather than always treating accesses as non-secure or requiring full domain switching capability, the system partially applies non-secure domain treatment only to specific addresses, reducing the complexity burden while enabling required data sharing.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentEP2062145B1Memory access security management
Publication Date: 2010.10.13 ARM LTD
  • EP2062145B1 patent drawingFigure 1
  • EP2062145B1 patent drawingFigure 2
  • EP2062145B1 patent drawingFigure 3

AI summary

A data processing apparatus and method for generating access requests is provided. A bus master is provided which can operate either in a secure domain or a non-secure domain of the data processing apparatus, according to a signal received from external to the bus master. The signal is generated to be fixed during normal operation of the bus master. Control logic is provided which, when the bus master device is operating in a secure domain, is operable to generate a domain specifying signal associated with an access request generated by the bus master core indicating either secure or non-secure access, in dependence on either a default memory map or securely defined memory region descriptors. Thus, the bus master operating in a secure domain can generate both secure and non-secure accesses, without itself being able to switch between secure and non-secure operation.