Content Firewall Unit for Secure Memory Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The ARM ThrustZone technology lacks effective mechanisms to prevent secure contents from being copied to non-secure memory regions when a processing unit does not utilize its secure hardware and instruction set architecture, potentially leading to unauthorized access and data security breaches.

Innovation Solution

A semiconductor device with a content firewall unit that divides memory addresses into secure and non-secure regions, preventing writing of secure contents to non-secure addresses by transmitting error messages and using encryption to allow secure data to be written in non-secure regions securely, ensuring that only authorized processing units can access and write to secure data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a processing unit uses a programming register for ISA and cache without ARM ThrustZone, then ease of operation is improved, but secure contents may be copied to non-secure memory regions causing security vulnerabilities

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a memory path controller as an intermediary component between the processing unit and memory system. This controller includes a content firewall unit that interceptates memory access requests, checks whether the processing unit has proper secure authority, and blocks unauthorized writes to secure memory regions. This mediator enables normal processing operations while preventing security breaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the memory address space into secure and non-secure regions through the address region control unit. By dividing the address space and assigning different access permissions to different regions, the system allows processing units to operate freely in non-secure regions while protecting secure regions from unauthorized access, thus resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If ARM ThrustZone secure hardware is implemented, then data security is improved, but device complexity increases due to separate secure and normal worlds

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal memory path controller that serves multiple functions: it manages both secure and non-secure memory access, performs address region control, and executes content firewall operations. By consolidating these security and memory management functions into a single controller rather than requiring separate secure and normal processing paths, the system achieves high security while reducing device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The content firewall unit automatically checks secure authority and blocks unauthorized access without requiring separate secure processing hardware. The system uses existing processing units with added control logic that enables them to self-regulate their own access permissions, eliminating the need for completely separate secure processing environments and thereby reducing overall system complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If address space is divided into secure and non-secure regions, then security is improved, but device complexity increases due to additional control units

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the address region control functionality and content firewall operations into a single integrated memory path controller. Rather than adding separate control units for address management and content protection, the design combines these functions in one controller that handles both secure and non-secure memory access, thereby achieving enhanced security while minimizing the increase in device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10068110B2Semiconductor device including a content firewall unit that has a secure function
Publication Date: 2018.09.04 SAMSUNG ELECTRONICS CO LTD
  • US10068110B2 patent drawing
  • US10068110B2 patent drawing
  • US10068110B2 patent drawing

AI summary

A semiconductor device includes a first processing unit configured to perform a calculation by using data stored in a memory; and a memory path controller configured to communicate with the first processing unit and control the memory for the first processing unit to perform the calculation, wherein the memory path controller includes an address region control unit configured to divide an address space of the memory to include a secure address and a non-secure address and permit the first processing unit to access the secure address or the non-secure address, and a first content firewall unit connected with the address region control unit and configured to prevent the first processing unit from writing secure contents in the non-secure address.