Memory Partitioning in Programmable ICs for Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In programmable integrated circuits (ICs), managing shared memory access among multiple logic circuits is challenging due to conflicts and the difficulty in manually configuring access permissions, especially as the number of circuits increases, and there is a risk of malicious software violating intended memory access permissions.
Innovation Solution
A method and system for partitioning memory in programmable ICs using a user interface to define subsystems, master circuits, and memory segments with specific permissions, generating configuration data to enforce access control and implement circuit designs, including the use of mask-value pairs to restrict access to memory segments based on user-defined permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If manual configuration of memory access permissions is used, then flexibility in memory access control is improved, but device complexity and difficulty of configuration increase as the number of circuits increases
Solution Approach 1:
The memory is divided into multiple memory segments, each with its own access control entry. This segmentation allows independent configuration of access permissions for different memory regions, managing complexity by breaking down the overall access control into smaller, manageable units. Each segment can be independently configured and enforced by the memory management circuit.
Solution Approach 2:
A memory management circuit is introduced as an intermediary between master circuits and memory segments. This intermediary automatically enforces access control based on configuration data, eliminating the need for manual configuration of access permissions for each circuit-memory pair. The intermediary handles the complexity of access control enforcement, simplifying the overall system configuration.
2Ease of operation
If automatic generation of configuration data is used, then ease of operation is improved, but manufacturing precision may be compromised
Solution Approach 1:
The system uses self-service through automatic generation of configuration data from high-level partitioning specifications. The memory management circuit and configuration generation process automatically translate user-defined memory segments and permissions into detailed access control entries without manual intervention, improving ease of operation while maintaining precision through systematic automated processes.
Solution Approach 2:
The memory management circuit uses feedback mechanisms to verify access control enforcement. The circuit monitors memory access requests against the generated configuration data and enforces permissions accordingly, ensuring that automatically generated configuration data maintains the required precision in access control enforcement.
3Reliability
If memory access permissions are enforced, then reliability is improved, but device complexity increases due to additional control circuitry
Solution Approach 1:
The memory management circuit is designed with multi-functionality, handling both memory address decoding and access control enforcement in a unified structure. This universal approach consolidates multiple functions into a single circuit, improving reliability through consistent enforcement while minimizing the increase in device complexity by avoiding separate dedicated circuits for each function.
Data Source
AI summary
Various example implementations are directed to circuits and methods for partitioning a memory for a circuit design in a programmable IC. A user interface is provided for a user to define subsystems, master circuits, memory segments, and permissions for accessing the memory segments by the master circuits. For each defined memory segment, a respective access control entry is generated that includes data for determining master circuits that are permitted access to the memory segment by the user-defined permissions. A first portion of configuration data is generated that is configured to cause a memory management circuit in the programmable IC to enforce access to address ranges, corresponding to the respective memory segments, in a memory of the programmable IC according to the respective access control entries. A second portion of configuration data is generated that is configured to cause programmable resources of the programmable IC to implement the circuit design.


