Integrated Circuit Asymmetric Access Privileges

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing integrated circuits lack secure runtime control and protection mechanisms, allowing malware to potentially cause irreversible damage by overriding control settings and firmware during runtime, posing a security risk to both the IC and output components.

Innovation Solution

An integrated circuit with a configuration that allows an external processor to access a restricted subset of addressable ranges during runtime, providing controlled access through a restricted interface while maintaining secure boot-time access via an unrestricted interface, using a control unit and policy table to manage access permissions and prevent malicious actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the external processor is given runtime access to the IC addressable space, then the processor can control and protect the IC functionality during runtime, but malware running on the processor could access the IC and override control settings or firmware causing irreversible damage

Engineering Contradiction:
Improveruntime control accessVSAvoidmalware damage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The addressable space of the IC is segmented into multiple regions with different access permissions. The control unit divides the addressable space such that certain regions are accessible during runtime while other regions remain protected. This segmentation allows the processor to control IC functionality through accessible regions while preventing malware from accessing protected regions containing critical control settings and firmware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different regions of the addressable space are assigned different access qualities or permission levels. The control unit enforces local access policies where specific address ranges have restricted access during runtime while other ranges allow full access. This local quality differentiation enables runtime control operations in safe regions while maintaining security in critical regions.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If the IC allows full processor access to all address ranges during runtime, then the processor has complete control over the IC, but the security protection against malicious actions is compromised

Engineering Contradiction:
Improveprocessor control capabilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The addressable space is segmented into multiple regions with different access permissions. The control unit divides the addressable space such that certain regions are accessible during runtime while other regions remain protected. This segmentation allows the processor to control IC functionality through accessible regions while preventing malware from accessing protected regions containing critical control settings and firmware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The control unit acts as an intermediary between the processor and the IC addressable space. It mediates all access requests from the processor to the IC memory, enforcing access permissions and filtering requests based on the current operational state (boot vs. runtime). This intermediary mechanism enables the processor to have controlled access during runtime while maintaining security protections.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the IC restricts processor access to only ON/OFF control during runtime, then the security protection is maintained, but the processor control capability over the IC is insufficient

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessor control capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The addressable space is segmented into multiple regions with different access permissions. The control unit divides the addressable space such that certain regions are accessible during runtime while other regions remain protected. This segmentation allows the processor to control IC functionality through accessible regions while preventing malware from accessing protected regions containing critical control settings and firmware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access permissions to different address regions are dynamic based on the operational state of the IC. During boot, the processor can access all address ranges for loading firmware and configuration. During runtime, access permissions change to allow control of specific regions while protecting others. This dynamic permission adjustment enables both comprehensive control during initialization and restricted control during operation.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11809334B2Integrated circuit with asymmetric access privileges
Publication Date: 2023.11.07 CIRRUS LOGIC INC
  • US11809334B2 patent drawing
  • US11809334B2 patent drawing
  • US11809334B2 patent drawing

AI summary

An integrated circuit comprises first and second interfaces, an internal addressable space comprising a plurality of address ranges, and a control unit. Each of the first and second interfaces is coupled to the internal addressable space via the control unit. The control unit is configurable in a first state in which the control unit is configured to allow or deny the second interface access to a subset of the plurality of address ranges of the internal addressable space.