Integrated Circuit Security Resource Access Across Isolated OS Domains
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In integrated circuits with multiple processor cores, non-secure world operating systems can all access all security resources in a secure world operating system, leading to unfavorable resource isolation, and a failure in the secure world operating system prevents normal access for all non-secure world operating systems.
Innovation Solution
Each operating system domain is run on a processor core corresponding to that domain, with a first preset-state operating system processing security resource access requests for the second preset-state operating system within that domain, ensuring isolation between domains and preventing failures in one domain from affecting others.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If all non-secure world operating systems can access all security resources in a secure world operating system, then resource accessibility is improved, but resource isolation deteriorates
Solution Approach 1:
The patent divides the operating system into multiple independent domains (first operating system domain and second operating system domain), each with its own processor core and security resources. This segmentation allows each domain to independently manage its security resources while maintaining isolation from other domains, thus improving both resource accessibility within domains and resource isolation between domains.
2Device complexity
If a single secure world operating system serves all non-secure world operating systems, then system complexity is reduced, but reliability deteriorates
Solution Approach 1:
The patent segments the secure world operating system into multiple independent instances (first secure world operating system and second secure world operating system), each serving specific non-secure world operating systems. This segmentation ensures that a failure in one secure world operating system instance does not affect other instances, thereby improving system reliability while maintaining manageable complexity through modular architecture.
Solution Approach 2:
Each operating system domain is configured with specific local qualities - the first processor core runs the first operating system domain with its own security resources, while the second processor core runs the second operating system domain with its own security resources. This local quality differentiation allows each domain to operate independently with tailored security configurations, improving reliability without requiring a single complex centralized system.
3Productivity
If security resources are shared across all operating system domains, then resource utilization is improved, but security deteriorates
Solution Approach 1:
The patent segments security resources into domain-specific resources - the first operating system domain has its own security resources managed by the first secure world operating system, and the second operating system domain has its own security resources managed by the second secure world operating system. This segmentation enables each domain to efficiently utilize its dedicated security resources while preventing security risks from propagating across domains, thus improving both resource utilization and security.
Data Source
AI summary
Disclosed are a security resource access method for an integrated circuit and an electronic device, relating to the technical field of integrated circuits. The method includes: determining, on the integrated circuit, a processor core corresponding to each of a plurality of operating system domains; running a first preset-state operating system or a second preset-state operating system in the operating system domain by the processor core corresponding to the operating system domain; and processing a security resource access request of the second preset-state operating system in the operating system domain based on the first preset-state operating system in the operating system domain. According to technical solutions of this disclosure, it can be ensured that resources between different operating system domains are relatively isolated, and greatly enhancing security of a plurality of operating systems.


