Hardware IP Access Identity Switching for Multi-Content Memory Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods for organizing secure and non-secure content paths in user equipment (UE) lead to communication overhead between the non-secure CPU and the secure CPU, especially when handling multiple contents simultaneously.
Innovation Solution
The system employs multiple access identities for each hardware IP to access different memory ranges, allowing for efficient switching between secure and non-secure content paths without reconfiguring memory permissions between content processing cycles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional methods organize secure and non-secure content paths with frequent CPU switching, then memory isolation and security are maintained, but communication overhead between CPUs increases and processing efficiency decreases
Solution Approach 1:
The patent segments the memory access permissions by creating multiple access identities (first access identity, second access identity) for the same hardware IP. Each access identity is associated with different memory permission configurations - one for secure memory ranges and one for non-secure memory ranges. This segmentation allows the system to maintain memory isolation while avoiding frequent CPU switching by simply changing access identities.
Solution Approach 2:
The patent implements dynamic switching of access identities based on the content being processed. The system can dynamically select which access identity to use for each hardware IP depending on whether the current content requires secure or non-secure memory access, enabling flexible and efficient content path organization without rigid CPU switching.
2Reliability
If the system frequently switches between secure and non-secure CPUs to process multiple contents, then security is maintained, but communication overhead increases
Solution Approach 1:
The patent extracts the CPU switching operation from the security enforcement mechanism. Instead of requiring actual CPU context switches to enforce security boundaries, the system extracts security control to the access identity selection layer. The same CPU can operate in different security contexts by simply switching access identities, eliminating the time-consuming CPU switching overhead while maintaining security.
Solution Approach 2:
The access identity acts as an intermediary between the hardware IP and the memory system. Rather than directly switching CPUs to enforce security, the access identity mediates memory access permissions, allowing the system to maintain security boundaries without the overhead of actual CPU context switches.
3Device complexity
If the system uses a single access identity for hardware IP, then device complexity is reduced, but flexibility in accessing different memory ranges decreases
Solution Approach 1:
The patent makes the hardware IP universal by enabling it to access both secure and non-secure memory ranges through multiple access identities. The same hardware IP can be configured with different access identities that grant different memory permissions, allowing one IP to serve multiple security contexts and memory regions without requiring separate hardware instances.
Data Source
AI summary
The invention provides method and system for improving efficiency of protecting multi-content process. The system may cooperate with a memory, and may comprise one or more hardware IPs (intellectual properties) for content processing, one of the one or more IPs may be associated with multiple access identities. The memory may comprise multiple different ranges, each range may register an access of one of the multiple access identities as a permissible access. The method may comprise: selecting one of the access identities for processing a first content, and using the selected access identity when said IP accesses the memory during processing of the first content; selecting a different one of the access identities for processing a second content, and using the selected different access identity when said IP accesses the memory during processing of the second content.


