Coupler Watcher for Secure Memory Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing integrated circuit arrangements face challenges in protecting shared memory regions from unauthorized access by non-trusted processes, particularly in complex System on Chip (SoC) systems, where debug watchpoints and breakpoints are often implemented, increasing silicon area and limiting reusability for secure execution environments.

Innovation Solution

An integrated circuit arrangement with a coupler watcher system that sets independent address ranges for each computer bus, allowing access requests to be checked against predetermined ranges, generating a false access signal or interrupt to prevent unauthorized access, thereby providing a secure execution environment with minimal impact on silicon area and hardware cost.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a common secure execution environment (TrustZone) is implemented, then memory protection against non-trusted processes is achieved, but silicon area increases and reusability for debug purposes is lost

Engineering Contradiction:
Improvememory protectionVSAvoidsilicon area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent implements a multi-functional coupler watcher that serves both debug purposes (watchpoints/breakpoints) and security purposes (access control) using the same hardware infrastructure. The watchpoint unit can be configured to monitor bus transactions for debug analysis or to enforce memory protection policies, eliminating the need for separate dedicated security hardware and thus reducing silicon area consumption.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the debug watchpoint/breakpoint functionality with the security access control functionality into a single integrated coupler watcher mechanism. By combining these functions, the system achieves both debug capabilities and secure execution environment without requiring separate hardware blocks, thereby reducing the overall silicon area and avoiding the trade-off presented in the contradiction.

Inventive Principle:
Principle #5Merging (Combining)

2Difficulty of detecting and measuring

If debug watchpoints/breakpoints are implemented on internal buses, then on-chip data movements can be monitored, but the system complexity increases

Engineering Contradiction:
Improvedata movement monitoringVSAvoidsystem complexity
Core Design Contradiction:
Difficulty of detecting and measuringVSDevice complexity

Solution Approach 1:

The coupler watcher is designed to perform multiple functions using the same hardware resources: it can operate as a debug watchpoint unit to monitor bus transactions, as a security access control mechanism to enforce memory protection, or in combination modes. This multi-functionality reduces system complexity by avoiding redundant hardware while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The watchpoint unit leverages the existing bus monitoring infrastructure to serve both debug and security purposes. The system uses the natural bus transaction flow and existing address/master signals to implement monitoring functionality, rather than adding separate complex monitoring hardware, thus reducing overall system complexity while maintaining detection capabilities.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If independent address ranges are set for each computer bus, then access control precision is improved, but hardware configuration complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidhardware configuration
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements independent address range configuration for each computer bus (AHB, APB, USB, etc.) within the coupler watcher. Each bus can have its own programmable address registers and access control settings, allowing precise control over memory access permissions specific to that bus. This segmentation enables fine-grained access control without requiring a complete redesign of the entire memory protection system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system provides programmable address registers and control registers that can be configured through software to define custom address ranges and access policies for each bus. By changing the parameters stored in these registers rather than requiring complex hardware reconfiguration, the system achieves precise access control while keeping the hardware configuration relatively simple and flexible.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP1862908B9Integrated circuit arrangement, a method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement and a computer program product
Publication Date: 2010.08.04 INFINEON TECHNOLOGIES AG
  • EP1862908B9 patent drawingFigure 1
  • EP1862908B9 patent drawingFigure 2
  • EP1862908B9 patent drawingFigure 3

AI summary

An integrated circuit arrangement comprises • a plurality of circuit arrangement components, • at least one coupler coupling the circuit arrangement components, • a coupler watcher checking as to whether an access request to one or a plurality of the circuit arrangement components has a request address, that identifies at leas:: a part of the circuit arrangement component, to which access is requested, that lies within a predetermined address range, and, dependent on whether the request address lies within the predetermined address range, the coupler watcher accepts the access request or generates a false access signal.