Content Firewall Unit for Secure Memory Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The ARM ThrustZone technology lacks effective mechanisms to prevent secure contents from being copied to non-secure memory regions when a processing unit does not utilize its secure hardware and instruction set architecture, potentially leading to unauthorized access and data security breaches.
Innovation Solution
A semiconductor device with a content firewall unit that divides memory addresses into secure and non-secure regions, preventing writing of secure contents to non-secure addresses by transmitting error messages and using encryption to allow secure data to be written in non-secure regions securely, ensuring that only authorized processing units can access and write to secure data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a processing unit uses a programming register for ISA and cache without ARM ThrustZone, then ease of operation is improved, but secure contents may be copied to non-secure memory regions causing security vulnerabilities
Solution Approach 1:
The patent introduces a memory path controller as an intermediary component between the processing unit and memory system. This controller includes a content firewall unit that interceptates memory access requests, checks whether the processing unit has proper secure authority, and blocks unauthorized writes to secure memory regions. This mediator enables normal processing operations while preventing security breaches.
Solution Approach 2:
The patent segments the memory address space into secure and non-secure regions through the address region control unit. By dividing the address space and assigning different access permissions to different regions, the system allows processing units to operate freely in non-secure regions while protecting secure regions from unauthorized access, thus resolving the contradiction between ease of operation and security.
2Reliability
If ARM ThrustZone secure hardware is implemented, then data security is improved, but device complexity increases due to separate secure and normal worlds
Solution Approach 1:
The patent implements a universal memory path controller that serves multiple functions: it manages both secure and non-secure memory access, performs address region control, and executes content firewall operations. By consolidating these security and memory management functions into a single controller rather than requiring separate secure and normal processing paths, the system achieves high security while reducing device complexity.
Solution Approach 2:
The content firewall unit automatically checks secure authority and blocks unauthorized access without requiring separate secure processing hardware. The system uses existing processing units with added control logic that enables them to self-regulate their own access permissions, eliminating the need for completely separate secure processing environments and thereby reducing overall system complexity.
3Reliability
If address space is divided into secure and non-secure regions, then security is improved, but device complexity increases due to additional control units
Solution Approach 1:
The patent merges the address region control functionality and content firewall operations into a single integrated memory path controller. Rather than adding separate control units for address management and content protection, the design combines these functions in one controller that handles both secure and non-secure memory access, thereby achieving enhanced security while minimizing the increase in device complexity.
Data Source
AI summary
A semiconductor device includes a first processing unit configured to perform a calculation by using data stored in a memory; and a memory path controller configured to communicate with the first processing unit and control the memory for the first processing unit to perform the calculation, wherein the memory path controller includes an address region control unit configured to divide an address space of the memory to include a secure address and a non-secure address and permit the first processing unit to access the secure address or the non-secure address, and a first content firewall unit connected with the address region control unit and configured to prevent the first processing unit from writing secure contents in the non-secure address.


