Embedded System Mode Switching for Security and Performance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing embedded systems face performance penalties due to the need for continuous virtualization support, which is costly in terms of resources, especially in tiny embedded systems with limited capacity, and are vulnerable to security threats from open software platforms.
Innovation Solution
A method that allows an embedded system to dynamically switch between normal and protected modes, using a hypervisor only when security critical functions are required, thereby limiting performance impact and enhancing security through mode switching initiated by reboot processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If continuous virtualization support is used, then security isolation and protection are improved, but system performance deteriorates due to resource consumption
Solution Approach 1:
The patent implements dynamic switching between virtualized and non-virtualized modes based on operational requirements. The system transitions from a static virtualization state to a dynamic state where virtualization is activated only when security isolation is needed, thereby optimizing the balance between security and performance.
Solution Approach 2:
The system employs periodic or event-driven activation of virtualization modes rather than continuous operation. Virtualized mode is periodically activated when security critical functions are detected and deactivated when they are not needed, reducing unnecessary resource consumption while maintaining security when required.
2Reliability
If hypervisor is always active, then security monitoring and isolation are improved, but device complexity and resource requirements increase
Solution Approach 1:
The patent extracts the hypervisor from a always-active state and implements it as a conditional component. The hypervisor is loaded and activated only when security monitoring and isolation are required, removing it from the default system state and reducing complexity when not needed.
Solution Approach 2:
The system dynamically adjusts the presence and activity level of the hypervisor based on operational context. The hypervisor transitions between active and inactive states, allowing the system to adapt its complexity level to match actual security requirements.
3Object-affected harmful factors
If virtualized mode is used continuously, then protection from security threats is improved, but energy consumption increases
Solution Approach 1:
The system implements periodic activation of virtualized mode only when security threats are detected or security critical functions are executing. This periodic action reduces energy consumption by keeping the system in lower-power non-virtualized mode during normal operation while maintaining protection when needed.
Solution Approach 2:
The system dynamically adjusts its virtualization state based on security risk assessment and operational requirements. This dynamic state change allows the system to optimize energy consumption by avoiding continuous virtualization overhead while maintaining security protection when threats are present.
Data Source
AI summary
A method performed by an embedded system controlled by a CPU and capable of operating as a virtualized system under supervision of a hypervisor or as a non-virtualized system under supervision of an operating system, is provided. The embedded system is executed in a normal mode if no execution of any security critical function is required, where the normal mode execution is performed under supervision of the operating system. If a security critical function execution is required, where protected mode execution is performed under supervision of the hypervisor, the operating system is switching execution of the embedded system from normal mode to protected mode, by handing over the execution of the embedded system from the operating system to the hypervisor. When execution of the security critical function is no longer required by the system is switched from protected mode to normal mode, under supervision of the hypervisor.


