Memory Range Merging for Security-Aware Applications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing application configuration methods and interfaces for processors do not optimize the management of memory resources based on security levels, leading to inefficiencies in memory access and usage.

Innovation Solution

A method and interface that merge contiguous memory resources with the same security attribute values to optimize memory ranges, using a configuration interface that adjusts security attributes and generates memory range configuration data based on security levels, thereby optimizing memory usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If memory resources are managed with separate security attributes for each portion, then security control is improved, but the number of memory ranges increases and management complexity worsens

Engineering Contradiction:
Improvesecurity controlVSAvoidnumber of memory ranges
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges contiguous memory portions that share the same security attribute into a single memory range. The access controller is configured to combine multiple adjacent memory portions with identical security levels (e.g., all non-secure or all secure) into unified ranges, reducing the total number of ranges while preserving security control. This directly addresses the contradiction by combining granular security management with reduced complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If memory resources are merged into fewer ranges, then management efficiency is improved, but security control precision worsens

Engineering Contradiction:
Improvemanagement efficiencyVSAvoidsecurity control precision
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies local quality by allowing different security attributes to be assigned to different memory portions based on their specific security requirements. The access controller evaluates each memory portion's security attribute individually and only merges portions with matching attributes, ensuring that each memory region maintains its appropriate security level while benefiting from consolidated management where applicable.

Inventive Principle:
Principle #3Local quality

3Loss of time

If the number of memory ranges is reduced, then access time is improved, but the granularity of security management worsens

Engineering Contradiction:
Improveaccess timeVSAvoidgranularity of security management
Core Design Contradiction:
Loss of timeVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security range management where the access controller can adaptively merge or separate memory portions based on the security requirements of executing applications. The system dynamically evaluates security attributes and reconfigures memory ranges accordingly, providing both fast access through consolidated ranges and fine-grained security control when needed, thus resolving the contradiction between access speed and management granularity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4488833B1Configuring a memory
Publication Date: 2025.10.22 STMICROELECTRONICS INT NV
  • EP4488833B1 patent drawingFigure 1
  • EP4488833B1 patent drawingFigure 2
  • EP4488833B1 patent drawingFigure 3

AI summary

This description relates to a method of configuring a memory (230) for the execution of an application (210) adapted to be executed by a processor (220) and using at least two contiguous first and second memory resources associated with an application and placed in at least one memory area of ​​at least one memory (230), in which said method includes a step of merging said at least two first and second memory resources into a third memory resource, if said at least two first and second portions have the same value of the security attribute, the method further comprising a step of generating configuration data for memory ranges of a memory.