Firmware Access Isolation for Multi-OS Resource Partitioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for managing multiple operating systems in devices are inefficient, requiring rebooting to switch between OS configurations and lacking the ability to run multiple OS concurrently without significant processing and power resource overhead, making them unsuitable for resource-constrained devices like mobile communication devices.

Innovation Solution

An access isolation module in the firmware partitions device equipment, allocates resources to each OS using customized tables, and employs encryption to ensure data isolation between OS, allowing for concurrent operation without interference.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple operating systems are run concurrently using virtualization, then the flexibility to run multiple OS at the same time is improved, but the processing power and battery life are worsened due to resource overhead

Engineering Contradiction:
Improveflexibility to run multiple OSVSAvoidbattery life
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The patent segments device equipment into distinct portions accessible to different operating systems using firmware-based access isolation modules. Each OS is assigned specific equipment portions through customized tables, allowing concurrent operation without full virtualization overhead. This segmentation enables multiple OS to run simultaneously while consuming fewer resources than complete virtualization would require.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If a device is rebooted to change OS configuration, then the OS switching capability is improved, but the time efficiency is worsened due to reboot delays

Engineering Contradiction:
ImproveOS switching capabilityVSAvoidreboot delay
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-configuring access isolation modules and equipment allocation tables in firmware before operating systems are launched. The firmware establishes equipment portions and access rules in advance, allowing operating systems to be switched between immediately without requiring system reboots. This pre-establishment of access isolation enables rapid OS transitions while maintaining proper resource separation.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If equipment is shared between multiple operating systems, then the resource utilization is improved, but the security and stability are worsened due to potential interference

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity and stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces firmware-based access isolation modules as intermediaries between operating systems and device equipment. These modules act as mediators that manage equipment access, allocating specific portions of equipment to each OS through customized tables. The intermediary firmware layer ensures that operating systems can share resources efficiently while maintaining security boundaries and preventing interference, as the access isolation module controls and monitors all equipment access requests.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10684865B2Access isolation for multi-operating system devices
Publication Date: 2020.06.16 INTEL CORP
  • US10684865B2 patent drawing
  • US10684865B2 patent drawing
  • US10684865B2 patent drawing

AI summary

The present application is directed to access isolation for multi-operating system devices. In general, a device may be configured using firmware to accommodate more than one operating system (OS) operating concurrently on the device or to transition from one OS to another. An access isolation module (AIM) in the firmware may determine a device equipment configuration and may partition the equipment for use by multiple operating systems. The AIM may disable OS-based equipment sensing and may allocate at least a portion of the equipment to each OS using customized tables. When transitioning between operating systems, the AIM may help to ensure that information from one OS is not accessible to others. For example, the AIM may detect when a foreground OS is to be replaced by a background OS, and may protect (e.g., lockout or encrypt) the files of the foreground OS prior to the background OS becoming active.