Centralized Access Control Circuit for SoC Peripheral Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing number of processor cores and peripherals on a system-on-chip (SoC) leads to a distributed architecture of hardware security units, resulting in increased area, fabrication costs, power consumption, and latency, with poor scalability as peripherals must be protected during the design phase and cannot be dynamically secured post-fabrication.
Innovation Solution
A centralized access control circuit that manages access privileges for processor cores using a memory with lock bits mapped to peripheral registers, allowing for dynamic control of access levels and protection configurations, integrating peripheral and register-level protection within a single hardware circuit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If distributed hardware security units are installed proximate to each peripheral, then peripheral protection is provided, but the area of the SoC increases
Solution Approach 1:
The patent combines multiple distributed hardware security units into a single centralized access control circuit that serves all peripherals. This consolidation maintains security functionality while reducing the total area occupied by security infrastructure on the SoC.
Solution Approach 2:
The centralized access control circuit is designed to provide security protection for multiple peripherals through a single unit. This multi-functional approach allows one security circuit to perform the roles that would otherwise require multiple separate security units distributed across the chip.
2Reliability
If distributed hardware security units are installed proximate to each peripheral, then peripheral protection is provided, but fabrication costs increase
Solution Approach 1:
The patent combines multiple distributed hardware security units into a single centralized access control circuit that serves all peripherals. This consolidation maintains security functionality while reducing the total area occupied by security infrastructure on the SoC.
3Reliability
If distributed hardware security units are installed proximate to each peripheral, then peripheral protection is provided, but power consumption increases
Solution Approach 1:
The patent combines multiple distributed hardware security units into a single centralized access control circuit that serves all peripherals. This consolidation maintains security functionality while reducing the total area occupied by security infrastructure on the SoC.
4Reliability
If distributed hardware security units are installed proximate to each peripheral, then peripheral protection is provided, but latency for read and write operations increases
Solution Approach 1:
The centralized access control circuit is designed to provide security protection for multiple peripherals through a single unit. This multi-functional approach allows one security circuit to perform the roles that would otherwise require multiple separate security units distributed across the chip.
5Reliability
If hardware security units are installed during the design phase for specific peripherals, then those peripherals are protected, but scalability is poor as additional peripherals cannot be protected post-fabrication
Solution Approach 1:
The patent implements a dynamic access control system where the centralized circuit can be configured to protect different peripherals as needed. This allows the protection scheme to adapt to changing requirements and new peripherals added post-fabrication, unlike static distributed security units that are hardwired to specific peripherals during design.
Data Source
AI summary
A centralized access control circuit includes a memory, a sub-circuit, and a memory controller. The memory includes a plurality of lock bits mapped to a plurality of bytes of a peripheral register included in a peripheral. The sub-circuit receives, from a processor core, an access request to access a set of bytes of the plurality of bytes. The sub-circuit grants a first level of access privilege to the processor core based on an identifier of the processor core and an address of the set of bytes included in the access request. The memory controller receives the access request and grants, based on a value of each of a set of lock bits mapped to the set of bytes, a second level of access privilege to the processor core. The processor core accesses the set of bytes based on the first and second levels of access privileges.


