Hardware IP Access Identity Switching for Multi-Content Memory Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for organizing secure and non-secure content paths in user equipment (UE) lead to communication overhead between the non-secure CPU and the secure CPU, especially when handling multiple contents simultaneously.

Innovation Solution

The system employs multiple access identities for each hardware IP to access different memory ranges, allowing for efficient switching between secure and non-secure content paths without reconfiguring memory permissions between content processing cycles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional methods organize secure and non-secure content paths with frequent CPU switching, then memory isolation and security are maintained, but communication overhead between CPUs increases and processing efficiency decreases

Engineering Contradiction:
Improvememory isolationVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the memory access permissions by creating multiple access identities (first access identity, second access identity) for the same hardware IP. Each access identity is associated with different memory permission configurations - one for secure memory ranges and one for non-secure memory ranges. This segmentation allows the system to maintain memory isolation while avoiding frequent CPU switching by simply changing access identities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements dynamic switching of access identities based on the content being processed. The system can dynamically select which access identity to use for each hardware IP depending on whether the current content requires secure or non-secure memory access, enabling flexible and efficient content path organization without rigid CPU switching.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the system frequently switches between secure and non-secure CPUs to process multiple contents, then security is maintained, but communication overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the CPU switching operation from the security enforcement mechanism. Instead of requiring actual CPU context switches to enforce security boundaries, the system extracts security control to the access identity selection layer. The same CPU can operate in different security contexts by simply switching access identities, eliminating the time-consuming CPU switching overhead while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The access identity acts as an intermediary between the hardware IP and the memory system. Rather than directly switching CPUs to enforce security, the access identity mediates memory access permissions, allowing the system to maintain security boundaries without the overhead of actual CPU context switches.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If the system uses a single access identity for hardware IP, then device complexity is reduced, but flexibility in accessing different memory ranges decreases

Engineering Contradiction:
Improveaccess identity managementVSAvoidmemory access flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent makes the hardware IP universal by enabling it to access both secure and non-secure memory ranges through multiple access identities. The same hardware IP can be configured with different access identities that grant different memory permissions, allowing one IP to serve multiple security contexts and memory regions without requiring separate hardware instances.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250181523A1Method and system for improving efficiency of protecting a multi-content process
Publication Date: 2025.06.05 MEDIATEK INC
  • US20250181523A1 patent drawing
  • US20250181523A1 patent drawing
  • US20250181523A1 patent drawing

AI summary

The invention provides method and system for improving efficiency of protecting multi-content process. The system may cooperate with a memory, and may comprise one or more hardware IPs (intellectual properties) for content processing, one of the one or more IPs may be associated with multiple access identities. The memory may comprise multiple different ranges, each range may register an access of one of the multiple access identities as a permissible access. The method may comprise: selecting one of the access identities for processing a first content, and using the selected access identity when said IP accesses the memory during processing of the first content; selecting a different one of the access identities for processing a second content, and using the selected different access identity when said IP accesses the memory during processing of the second content.