Distributed Memory Access Control for Isolated Region Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory access control mechanisms in computing systems are costly due to increased complexity, power usage, and latency issues, particularly in protecting isolated memory regions, as they require extensive hardware and configuration for numerous devices and access points.

Innovation Solution

Distribute isolated memory region access control registers across multiple access points, optimizing them to store only address range information and device permissions relevant to connected devices, reducing storage requirements and latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional memory access control mechanisms are implemented with multiple devices accessing shared memory, then memory protection is provided, but hardware cost, power usage, and gate count increase significantly

Engineering Contradiction:
Improvememory protectionVSAvoidhardware cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the monolithic access control structure into distributed access control entries distributed across multiple memory locations. Each access control entry is divided into multiple segments stored at different memory locations, eliminating the need for a single large centralized access control table and reducing hardware complexity while maintaining protection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested structure where access control entries are organized in a hierarchical manner with base addresses, limit addresses, and access rights nested within a structured format. This nesting allows compact representation of access control information, reducing the overall memory footprint and gate count while providing comprehensive protection.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If isolated memory regions are protected with detailed access control information for each device, then security is improved, but register storage requirements and configuration overhead increase

Engineering Contradiction:
ImprovesecurityVSAvoidregister storage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent applies local quality by storing access control information locally at distributed memory locations rather than centrally. Each access control entry is placed near the memory region it protects, allowing devices to access control information locally without requiring large centralized register files, thus reducing overall register storage requirements.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent uses copying by distributing copies of access control entries across multiple memory locations rather than storing a single master copy in registers. This eliminates the need for large register files to store complete access control information for all devices, significantly reducing register storage requirements while maintaining security through distributed verification.

Inventive Principle:
Principle #26Copying

3Reliability

If access control checks are performed at the destination side near memory interface, then protection is provided, but bandwidth decreases and latency increases

Engineering Contradiction:
ImproveprotectionVSAvoidbandwidth
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by pre-configuring access control entries in distributed memory locations before access requests are made. Access control information is prepared and stored in advance at appropriate memory locations, allowing devices to perform self-verification without requiring real-time intervention from memory management units, thus maintaining high bandwidth and low latency while providing protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12614003B2Distributed system on a chip memory access control
Publication Date: 2026.04.28 INTEL CORP
  • US12614003B2 patent drawing
  • US12614003B2 patent drawing
  • US12614003B2 patent drawing

AI summary

Embodiments described herein may include apparatus, systems, techniques, or processes that are directed to access control mechanisms used to protect isolated memory regions. Embodiments described herein enable a distributed and efficient register structure enabling system providers to reduce cost and improve system performance while preventing malicious devices from accessing isolated memory regions. Isolated memory region access control registers are distributed through multiple access points or bridges but each may be optimized and minimized to allow fast and efficient access control. Other embodiments may be described and/or claimed.