Integrated Circuit Security Resource Access Across Isolated OS Domains

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In integrated circuits with multiple processor cores, non-secure world operating systems can all access all security resources in a secure world operating system, leading to unfavorable resource isolation, and a failure in the secure world operating system prevents normal access for all non-secure world operating systems.

Innovation Solution

Each operating system domain is run on a processor core corresponding to that domain, with a first preset-state operating system processing security resource access requests for the second preset-state operating system within that domain, ensuring isolation between domains and preventing failures in one domain from affecting others.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If all non-secure world operating systems can access all security resources in a secure world operating system, then resource accessibility is improved, but resource isolation deteriorates

Engineering Contradiction:
Improveresource accessibilityVSAvoidresource isolation
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the operating system into multiple independent domains (first operating system domain and second operating system domain), each with its own processor core and security resources. This segmentation allows each domain to independently manage its security resources while maintaining isolation from other domains, thus improving both resource accessibility within domains and resource isolation between domains.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a single secure world operating system serves all non-secure world operating systems, then system complexity is reduced, but reliability deteriorates

Engineering Contradiction:
Improvesystem complexityVSAvoidsystem reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the secure world operating system into multiple independent instances (first secure world operating system and second secure world operating system), each serving specific non-secure world operating systems. This segmentation ensures that a failure in one secure world operating system instance does not affect other instances, thereby improving system reliability while maintaining manageable complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each operating system domain is configured with specific local qualities - the first processor core runs the first operating system domain with its own security resources, while the second processor core runs the second operating system domain with its own security resources. This local quality differentiation allows each domain to operate independently with tailored security configurations, improving reliability without requiring a single complex centralized system.

Inventive Principle:
Principle #3Local quality

3Productivity

If security resources are shared across all operating system domains, then resource utilization is improved, but security deteriorates

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments security resources into domain-specific resources - the first operating system domain has its own security resources managed by the first secure world operating system, and the second operating system domain has its own security resources managed by the second secure world operating system. This segmentation enables each domain to efficiently utilize its dedicated security resources while preventing security risks from propagating across domains, thus improving both resource utilization and security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250307384A1Security Resource Access Method For Integrated Circuit, And Electronic Device
Publication Date: 2025.10.02 HORIZON JOURNEY (HANGZHOU) ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD
  • US20250307384A1 patent drawing
  • US20250307384A1 patent drawing
  • US20250307384A1 patent drawing

AI summary

Disclosed are a security resource access method for an integrated circuit and an electronic device, relating to the technical field of integrated circuits. The method includes: determining, on the integrated circuit, a processor core corresponding to each of a plurality of operating system domains; running a first preset-state operating system or a second preset-state operating system in the operating system domain by the processor core corresponding to the operating system domain; and processing a security resource access request of the second preset-state operating system in the operating system domain based on the first preset-state operating system in the operating system domain. According to technical solutions of this disclosure, it can be ensured that resources between different operating system domains are relatively isolated, and greatly enhancing security of a plurality of operating systems.