System-on-Chip DMA Controller Segmentation for Secure Access Routing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional direct memory access controllers in system-on-chips require complex programming to manage access rights for each channel, leading to performance deterioration and potential erroneous configurations due to frequent reassignment of channels based on peripheral access rights.

Innovation Solution

A system-on-chip design incorporating a direct memory access circuit with physically separated secure and non-secure controllers, utilizing a routing circuit to dynamically couple peripherals based on their access rights, eliminating the need for reprogramming and simplifying the controller design.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single direct memory access controller is used for both secure and non-secure peripherals, then device complexity is reduced, but reliability deteriorates due to potential erroneous programming and security violations

Engineering Contradiction:
Improvecontroller designVSAvoidaccess right management
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The direct memory access circuit is segmented into multiple controllers: at least one first direct memory access controller with first access rights for secure peripherals, and at least one second direct memory access controller with second access rights for non-secure peripherals. This segmentation ensures that each controller is dedicated to specific security domains, preventing erroneous programming and security violations while maintaining clear separation of duties.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each controller is assigned specific local qualities in terms of access rights: the first controller has first access rights level configured for secure operations, while the second controller has second access rights level configured for non-secure operations. This local quality assignment ensures that each controller operates within its designated security boundaries, improving reliability without requiring complex global coordination.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If access rights are dynamically reconfigured for each peripheral use, then adaptability is improved, but productivity deteriorates due to frequent reprogramming operations

Engineering Contradiction:
Improveaccess right assignmentVSAvoiddata transfer efficiency
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The routing circuit is pre-configured with routing rules that automatically direct data transfers from secure peripherals to the first controller and from non-secure peripherals to the second controller. This preliminary configuration eliminates the need for dynamic reprogramming during operation, maintaining high productivity while still providing adaptability through the automated routing logic.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The routing circuit autonomously determines which controller should handle each data transfer based on the peripheral's security classification, without requiring external reprogramming or intervention. This self-service mechanism maintains adaptability by automatically routing transfers appropriately while preserving productivity by eliminating reconfiguration overhead.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple controllers are used with separate access rights, then reliability is improved through security isolation, but device complexity increases due to multiple controllers

Engineering Contradiction:
Improvesecurity isolationVSAvoidcontroller architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The routing circuit acts as an intermediary that automatically directs data transfers to the appropriate controller based on security requirements. This intermediary simplifies the overall architecture by providing a centralized routing mechanism that manages the complexity of multiple controllers, ensuring security isolation is maintained without requiring each peripheral to directly manage controller complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If frequent reassignment of channels is performed, then adaptability is improved, but loss of time increases due to reprogramming operations

Engineering Contradiction:
Improvechannel assignmentVSAvoidreconfiguration time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The routing circuit is pre-configured with routing rules that enable immediate automatic direction of data transfers to the correct controller based on peripheral security classification. This preliminary setup eliminates the need for time-consuming reprogramming operations during runtime, maintaining adaptability through automated routing while preventing time loss by avoiding repeated configuration cycles.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12360684B2System-on-chip incorporating a direct memory access circuit and corresponding method
Publication Date: 2025.07.15 STMICROELECTRONICS (ROUSSET) SAS
  • US12360684B2 patent drawing
  • US12360684B2 patent drawing

AI summary

In accordance with an embodiment, a system-on-chip includes: a memory circuit comprising a first memory region accessible with a first access right level and a second memory region accessible with the first access right level or a second access right level, at least one first peripheral having the first access right level, at least one second peripheral having the second access right level; and a direct memory access circuit configured to generate direct memory accesses, wherein the direct memory access circuit includes at least one first direct memory access controller having the first access right level and at least one second direct memory access controller having the second access right level.