Hardware Component Access via Task Control Interfaces Across Security States

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely and efficiently managing hardware components like ML accelerators across multiple security states in computing environments with virtualization and compartmentalization, leading to increased complexity and latency.

Innovation Solution

Implementing hardware-based task control interfaces (TCIs) managed by a primary management interface (PMI) to facilitate access and configuration of hardware components across secure, non-secure, and realm worlds without the need for complex device drivers, ensuring secure and efficient management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If complex device drivers are implemented to manage hardware components across multiple security states, then accessibility and functionality are improved, but device complexity and overhead increase

Engineering Contradiction:
Improvehardware component accessibilityVSAvoiddevice driver complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the security state management functionality from complex device drivers and implements it directly in hardware. The hardware component includes circuitry that natively supports multiple security states (secure, non-secure, and realm worlds), eliminating the need for software-based management layers and reducing overall system complexity while maintaining full accessibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The hardware component is designed with universal interfaces that can be accessed by software components across all security states simultaneously. The single hardware component performs multiple functions by responding to requests from different security contexts without requiring separate management drivers for each state, thereby reducing complexity while enhancing adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If cross-communication between multiple security states is enabled for hardware access, then functionality and accessibility are improved, but latency and overhead increase

Engineering Contradiction:
Improvesoftware component accessibilityVSAvoidaccess latency
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments the access control logic into dedicated hardware pathways for each security state. The hardware component includes separate interface circuits that can independently handle requests from secure world, non-secure world, and realm world software components simultaneously, allowing parallel processing of access requests and eliminating sequential overhead.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware component implements self-service mechanisms where each security state has direct, autonomous access to the hardware through dedicated interfaces. The hardware automatically manages state transitions and access permissions without requiring inter-communication or coordination between security states, thereby eliminating communication overhead and reducing latency.

Inventive Principle:
Principle #25Self-service

3Productivity

If simplified hardware-based interfaces are used for hardware component access, then overhead and latency are reduced, but management flexibility and control may be limited

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidconfiguration flexibility
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The hardware-based task control interface includes dynamic configuration capabilities where interface parameters, access permissions, and operational modes can be modified in real-time based on system state and security requirements. The hardware responds adaptively to different request types from various security states, maintaining full configuration flexibility while operating through streamlined hardware pathways that minimize overhead.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12380200B2System, devices and/or processes for assignment, configuration and/or management of one or more hardware components of a computing device
Publication Date: 2025.08.05 ARM LTD
  • US12380200B2 patent drawing
  • US12380200B2 patent drawing
  • US12380200B2 patent drawing

AI summary

Briefly, example methods, apparatuses, and/or articles of manufacture are disclosed that may facilitate and/or support assignment, configuration and/or management of one or more hardware components of a computing device.