Integrated Circuit Access Protection via Group Tagging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern integrated circuits face challenges in efficiently protecting resources like IO ports, as existing access protection mechanisms require extensive hardware to manage various tagging mechanisms and are prone to misconfiguration and race conditions, especially when access rights are altered during runtime.

Innovation Solution

The proposed solution involves a centralized access protection scheme using a plurality of gating circuits and configuration registers, where tag evaluation circuits determine group identifiers for access requests, and comparison circuits control access based on configuration register information, allowing for efficient grouping of access rights and reducing verification complexity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a centralized access protection scheme with grouping is used, then device complexity is reduced, but protection granularity may be reduced

Engineering Contradiction:
Improvehardware complexityVSAvoidprotection granularity
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments access protection into hierarchical groups, where resources are organized into groups and access rights are defined at the group level rather than individual resource level. This segmentation reduces the complexity of access control logic while maintaining adequate protection through the group structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates universal group identifiers that can be applied across multiple resources and contexts. A single group identifier can protect multiple resources simultaneously, and the same protection mechanism serves both security enforcement and configuration management functions, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If extensive hardware is used for tagging mechanisms, then access protection capability is improved, but device complexity increases

Engineering Contradiction:
Improveaccess protection capabilityVSAvoidhardware burden
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex tagging and identification logic from individual resource protection circuits and consolidates it into a centralized tag evaluation circuit. This extraction allows simple gating circuits to enforce protection while the complex evaluation logic resides in a single dedicated unit, reducing overall hardware complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces group identifiers as an intermediary layer between detailed resource identification and access control decisions. Instead of directly comparing detailed tags with each resource, the system uses group identifiers as a mediator that simplifies the comparison process and reduces hardware requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If configuration is locked after supervising software sets it, then security is improved, but flexibility for runtime changes is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidruntime configuration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic access protection where group identifiers and configuration can be modified during runtime through controlled mechanisms. The system transitions from static pre-boot configuration to dynamic runtime reconfiguration, allowing security policies to adapt to changing operational requirements while maintaining protection integrity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent performs preliminary configuration of group identifiers and access rights during system initialization and boot-up phases. This preliminary action establishes a secure baseline configuration that can later be safely modified through controlled runtime mechanisms, ensuring both initial security and subsequent flexibility.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240004992A1Resource protection
Publication Date: 2024.01.04 INFINEON TECHNOLOGIES AG
  • US20240004992A1 patent drawing
  • US20240004992A1 patent drawing
  • US20240004992A1 patent drawing

AI summary

In an embodiment an integrated circuit comprises a plurality of ports. Of a plurality of gating circuits, each gating circuit blocks or grants access to at least one of the ports depending on a release signal. From a plurality of configuration registers, each configuration register for stores the information to which group a gating circuit of the plurality of gating circuits belongs. A tag evaluation circuit receives an identifier from an access request from a component and outputs a group identifier for the access. There is a plurality of comparison circuits. Each comparison circuit compares the group identifier with the content of one of the configuration registers and outputs the release signal to a gating circuit of the plurality of gating circuits.