Integrated Circuit Asymmetric Access Privileges
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing integrated circuits lack secure runtime control and protection mechanisms, allowing malware to potentially cause irreversible damage by overriding control settings and firmware during runtime, posing a security risk to both the IC and output components.
Innovation Solution
An integrated circuit with a configuration that allows an external processor to access a restricted subset of addressable ranges during runtime, providing controlled access through a restricted interface while maintaining secure boot-time access via an unrestricted interface, using a control unit and policy table to manage access permissions and prevent malicious actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the external processor is given runtime access to the IC addressable space, then the processor can control and protect the IC functionality during runtime, but malware running on the processor could access the IC and override control settings or firmware causing irreversible damage
Solution Approach 1:
The addressable space of the IC is segmented into multiple regions with different access permissions. The control unit divides the addressable space such that certain regions are accessible during runtime while other regions remain protected. This segmentation allows the processor to control IC functionality through accessible regions while preventing malware from accessing protected regions containing critical control settings and firmware.
Solution Approach 2:
Different regions of the addressable space are assigned different access qualities or permission levels. The control unit enforces local access policies where specific address ranges have restricted access during runtime while other ranges allow full access. This local quality differentiation enables runtime control operations in safe regions while maintaining security in critical regions.
2Adaptability or versatility
If the IC allows full processor access to all address ranges during runtime, then the processor has complete control over the IC, but the security protection against malicious actions is compromised
Solution Approach 1:
The addressable space is segmented into multiple regions with different access permissions. The control unit divides the addressable space such that certain regions are accessible during runtime while other regions remain protected. This segmentation allows the processor to control IC functionality through accessible regions while preventing malware from accessing protected regions containing critical control settings and firmware.
Solution Approach 2:
The control unit acts as an intermediary between the processor and the IC addressable space. It mediates all access requests from the processor to the IC memory, enforcing access permissions and filtering requests based on the current operational state (boot vs. runtime). This intermediary mechanism enables the processor to have controlled access during runtime while maintaining security protections.
3Reliability
If the IC restricts processor access to only ON/OFF control during runtime, then the security protection is maintained, but the processor control capability over the IC is insufficient
Solution Approach 1:
The addressable space is segmented into multiple regions with different access permissions. The control unit divides the addressable space such that certain regions are accessible during runtime while other regions remain protected. This segmentation allows the processor to control IC functionality through accessible regions while preventing malware from accessing protected regions containing critical control settings and firmware.
Solution Approach 2:
The access permissions to different address regions are dynamic based on the operational state of the IC. During boot, the processor can access all address ranges for loading firmware and configuration. During runtime, access permissions change to allow control of specific regions while protecting others. This dynamic permission adjustment enables both comprehensive control during initialization and restricted control during operation.
Data Source
AI summary
An integrated circuit comprises first and second interfaces, an internal addressable space comprising a plurality of address ranges, and a control unit. Each of the first and second interfaces is coupled to the internal addressable space via the control unit. The control unit is configurable in a first state in which the control unit is configured to allow or deny the second interface access to a subset of the plurality of address ranges of the internal addressable space.


