Dynamic Privilege Controller for Secure Memory Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for providing direct memory access (DMA) to hardware components in electronic devices are susceptible to security issues, as they may allow unsecure software to access restricted memory areas once the hardware is promoted to a privileged level.

Innovation Solution

An electronic device with a processor and a hardware module that operate at variable privilege levels, where the secure memory area is accessible only when the module's privilege level exceeds a threshold, and a controller manages privilege promotions and demotions to ensure secure access, allowing the hardware module to maintain privileged access even when the processor is in a lower privilege mode.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the hardware component is promoted to a privileged level to allow direct access to secure memory areas, then memory access efficiency is improved, but security is worsened as unsecure software may exploit this to access restricted memory areas

Engineering Contradiction:
Improvememory access efficiencyVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic privilege level adjustment for the hardware component based on the processor's current privilege level. The hardware component's privilege level is no longer static but changes dynamically in response to processor state, allowing it to access secure memory only when the processor is in a secure state, thus resolving the contradiction between access efficiency and security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes a feedback mechanism where the processor's privilege level state is continuously monitored and used to control the hardware component's access privileges. This feedback loop ensures that the hardware component can only access secure memory when the processor is in a secure state, preventing exploitation by unsecure software while maintaining efficient direct memory access when appropriate

Inventive Principle:
Principle #23Feedback

2Reliability

If the processor operates continuously in a privileged mode to maintain hardware component access, then security is improved, but power consumption increases

Engineering Contradiction:
ImprovesecurityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent enables the processor to dynamically switch between privileged and unprivileged modes based on operational requirements. The hardware component's privilege level adjusts accordingly, allowing the processor to operate in low-power unprivileged mode when secure memory access is not needed, thus reducing power consumption while maintaining security when required

Inventive Principle:
Principle #15Dynamics

3Productivity

If the hardware component maintains privileged access continuously, then resource utilization efficiency is improved, but security risk increases

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements conditional privilege maintenance where the hardware component's privileged access is sustained only while the processor remains in a secure state. This dynamic privilege management allows efficient resource utilization during secure operations while automatically reducing security risk when the processor transitions to unprivileged mode, preventing continuous privileged access exploitation

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11403003B2Memory access
Publication Date: 2022.08.02 NORDIC SEMICONDUCTOR
  • US11403003B2 patent drawing
  • US11403003B2 patent drawing
  • US11403003B2 patent drawing

AI summary

An electronic device comprises a processor operable at a variable processor privilege level and a memory comprising a secure memory area. A hardware module is operable at a variable module privilege level and is arranged to access the memory directly. The secure memory area is accessible by the hardware module only when the module privilege level exceeds a threshold value. The device has a first mode of operation in which said processor privilege level is higher than said threshold value and said module privilege level is lower than said threshold value. A controller is arranged, upon receiving a privilege promotion signal and the device being in the first mode, to move the device to a second mode wherein the module privilege level is higher than said threshold value.