DRAM Controller IOMMU with Secure Range Access Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional memory protection units (MPUs) have low memory utilization due to continuous secure address spaces, necessitating the use of an Input-Output Memory Management Unit (IOMMU) for improved memory protection and access control.

Innovation Solution

A system on chip (SoC) incorporating a DRAM controller with a secure range permission checker, IOMMU and IOMPU tables, and IP cores, which manage access permissions using secure range information (SR_info) to enable efficient memory protection and isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional generic memory protection unit (MPU) is used with continuous address space for secure ranges, then memory protection is provided, but memory utilization is low

Engineering Contradiction:
Improvememory protectionVSAvoidmemory utilization
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent segments the continuous address space into discrete secure ranges with start and end addresses. Each secure range is independently managed in the SR table, allowing non-secure gaps between them. This segmentation enables precise access control while maximizing memory utilization by avoiding the need for continuous secure address spaces.

Inventive Principle:
Principle #1Segmentation

2Quantity of substance

If IOMMU is used to improve memory utilization, then memory protection and access control is enhanced, but device complexity increases

Engineering Contradiction:
Improvememory utilizationVSAvoiddevice complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The patent embeds the secure range permission checker directly within the DRAM controller, creating a nested structure where the permission checker is integrated into the existing memory control architecture. This nesting approach enhances memory protection functionality while minimizing additional device complexity by leveraging the existing DRAM controller infrastructure.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Ease of operation

If secure ranges are configured as continuous address space, then memory protection is simplified, but memory utilization decreases

Engineering Contradiction:
Improvememory protection configurationVSAvoidmemory utilization
Core Design Contradiction:
Ease of operationVSQuantity of substance

Solution Approach 1:

The patent implements dynamic secure range management where the DRAM controller can identify and manage multiple discrete secure ranges with different start and end addresses. The secure range permission checker dynamically determines whether each access request falls within a secure range, enabling flexible memory allocation that maximizes utilization while maintaining protection simplicity through automated address validation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12455694B2Input-output memory management unit with memory protection
Publication Date: 2025.10.28 MEDIATEK INC
  • US12455694B2 patent drawing
  • US12455694B2 patent drawing
  • US12455694B2 patent drawing

AI summary

A system on chip includes a dynamic random access memory (DRAM) controller, a secure range (SR) permission checker, a plurality of intellectual property (IP) cores. The DRAM controller includes a SR table configured to store a start address, an end address, and enabled registers of each SR and an access identification (AID) permission table configured to store access permissions of SRs of each AID. The SR permission checker is embedded in the DRAM controller or a bus and linked to the SR table and the AID permission table, and configured to check the access permissions of the SRs according to the AID permission table. The plurality of IP cores linked to the DRAM controller, and comprising a translation lookaside buffer (TLB) comprising an input-output memory management unit (IOMMU) table or an input-output memory protection unit (IOMPU) table to store SR information.