Embedded System Mode Switching for Security and Performance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing embedded systems face performance penalties due to the need for continuous virtualization support, which is costly in terms of resources, especially in tiny embedded systems with limited capacity, and are vulnerable to security threats from open software platforms.

Innovation Solution

A method that allows an embedded system to dynamically switch between normal and protected modes, using a hypervisor only when security critical functions are required, thereby limiting performance impact and enhancing security through mode switching initiated by reboot processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If continuous virtualization support is used, then security isolation and protection are improved, but system performance deteriorates due to resource consumption

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic switching between virtualized and non-virtualized modes based on operational requirements. The system transitions from a static virtualization state to a dynamic state where virtualization is activated only when security isolation is needed, thereby optimizing the balance between security and performance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic or event-driven activation of virtualization modes rather than continuous operation. Virtualized mode is periodically activated when security critical functions are detected and deactivated when they are not needed, reducing unnecessary resource consumption while maintaining security when required.

Inventive Principle:
Principle #19Periodic action

2Reliability

If hypervisor is always active, then security monitoring and isolation are improved, but device complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidhypervisor involvement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the hypervisor from a always-active state and implements it as a conditional component. The hypervisor is loaded and activated only when security monitoring and isolation are required, removing it from the default system state and reducing complexity when not needed.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system dynamically adjusts the presence and activity level of the hypervisor based on operational context. The hypervisor transitions between active and inactive states, allowing the system to adapt its complexity level to match actual security requirements.

Inventive Principle:
Principle #15Dynamics

3Object-affected harmful factors

If virtualized mode is used continuously, then protection from security threats is improved, but energy consumption increases

Engineering Contradiction:
Improvesecurity threatsVSAvoidenergy consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The system implements periodic activation of virtualized mode only when security threats are detected or security critical functions are executing. This periodic action reduces energy consumption by keeping the system in lower-power non-virtualized mode during normal operation while maintaining protection when needed.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system dynamically adjusts its virtualization state based on security risk assessment and operational requirements. This dynamic state change allows the system to optimize energy consumption by avoiding continuous virtualization overhead while maintaining security protection when threats are present.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9189247B2Method for switching between virtualized and non-virtualized system operation
Publication Date: 2015.11.17 TELEFONAKTIEBOLAGET LM ERICSSON (PUBL)
  • US9189247B2 patent drawing
  • US9189247B2 patent drawing
  • US9189247B2 patent drawing

AI summary

A method performed by an embedded system controlled by a CPU and capable of operating as a virtualized system under supervision of a hypervisor or as a non-virtualized system under supervision of an operating system, is provided. The embedded system is executed in a normal mode if no execution of any security critical function is required, where the normal mode execution is performed under supervision of the operating system. If a security critical function execution is required, where protected mode execution is performed under supervision of the hypervisor, the operating system is switching execution of the embedded system from normal mode to protected mode, by handing over the execution of the embedded system from the operating system to the hypervisor. When execution of the security critical function is no longer required by the system is switched from protected mode to normal mode, under supervision of the hypervisor.