Integrated Circuit Access Isolation Using Fused Application IDs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In intelligent driving chips, existing methods fail to isolate applications with different functional security levels due to identical identification information in access requests, leading to inadequate isolation of slave devices.

Innovation Solution

An integrated circuit and method that determines fused identification information for each application, matches it with preset identification information stored in isolation units, and isolates target slave devices based on this matching, ensuring secure access control for applications with varying security levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If identical identification information is used in access requests for all applications, then the system structure is simple, but the firewall unit cannot isolate applications with different functional security levels

Engineering Contradiction:
Improveisolation effectivenessVSAvoididentification information structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The identification information is segmented into multiple fields: a first identification field indicating the main controller's identity and a second identification field indicating the application's identity. This segmentation allows the firewall unit to distinguish between different applications running on the same main controller, enabling effective isolation while maintaining a relatively simple overall structure.

Inventive Principle:
Principle #1Segmentation

2Reliability

If fused identification information is generated for each application, then precise isolation can be achieved, but the processing complexity increases

Engineering Contradiction:
Improveaccess control accuracyVSAvoidprocessing logic
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The fused identification information is generated in advance when the application is loaded or started, rather than being created dynamically during each access request. This preliminary action ensures that the firewall unit can perform accurate matching without complex real-time processing, balancing isolation accuracy with processing simplicity.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If dynamic identification information is used to improve isolation, then security is enhanced, but the switching speed may be reduced

Engineering Contradiction:
Improvesecurity levelVSAvoidaccess request processing speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The identification information structure is designed to be copied and attached to each access request without requiring complex generation or verification processes. The fused identification information acts as a simple tag that can be rapidly replicated and matched, maintaining high processing speed while enabling dynamic security isolation between applications.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250363229A1Integrated circuit and device access isolation method, medium and electronic device thereof
Publication Date: 2025.11.27 XG TECHNOLOGIES PTE LTD
  • US20250363229A1 patent drawing
  • US20250363229A1 patent drawing
  • US20250363229A1 patent drawing

AI summary

An integrated circuit and a device access isolation method, a medium, and an electronic device thereof are disclosed, and the method includes: determining fused identification information corresponding to a target application being run by a main controller; generating an access request carrying the fused identification information; determining preset identification information respectively stored in a plurality of isolation units corresponding to a plurality of slave devices; matching the preset identification information with the fused identification information; determining, based on a matching relationship between the preset identification information and the fused identification information, a target slave device to be isolated from the access request among the plurality of slave devices.