Microcontroller Secure Memory Isolation Cell

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems managing both 'safe' and 'no safe' applications on a microcontroller face performance degradation and high costs due to resource-intensive hypervisor use and certification requirements, necessitating a cost-effective solution for secure coexistence.

Innovation Solution

An electronic microcontroller system with a secure processor, shared memory access, and interconnection matrix, incorporating cells for secure memory isolation between user master peripherals and the interconnection matrix, which filters and verifies memory access to prevent unauthorized writes to protected addresses, reducing the need for extensive certification and resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a hypervisor is used to manage safe and no safe applications on the same microcontroller, then application coexistence is enabled, but system performance degrades and resource consumption increases

Engineering Contradiction:
Improveapplication coexistenceVSAvoidsystem performance
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system partitions the microcontroller into distinct secure and non-secure domains using TrustZone technology. The secure processor core handles safe applications while the non-secure core handles no safe applications, enabling application coexistence without the performance overhead of a hypervisor by physically separating execution environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure memory isolation cell acts as an intermediary between the user master peripheral and the interconnection matrix. This cell filters and verifies memory access requests, allowing safe and no safe applications to coexist by mediating their access to shared resources without requiring a resource-intensive hypervisor layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a hypervisor is used to manage safe and no safe applications, then application isolation is achieved, but certification requirements and costs increase

Engineering Contradiction:
Improveapplication isolationVSAvoidcertification requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system extracts the certification burden from the software layer by implementing hardware-enforced memory isolation. The secure memory isolation cell provides guaranteed isolation between safe and no safe applications at the hardware level, eliminating the need to certify complex hypervisor and operating system software while maintaining application isolation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention replaces expensive, complex certified software solutions with a simpler, hardware-based isolation mechanism. The secure memory isolation cell provides the necessary security guarantees through hardware enforcement rather than relying on expensive certified software layers, reducing overall system complexity and certification requirements.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Ease of operation

If memory access is allowed between user master peripheral and interconnection matrix, then system functionality is maintained, but security vulnerabilities arise

Engineering Contradiction:
Improvesystem functionalityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The secure memory isolation cell serves as an intermediary between the user master peripheral and the interconnection matrix. It transparently filters memory access requests, allowing legitimate functionality to proceed while blocking unauthorized access to protected memory regions, thus maintaining system functionality while eliminating security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements preliminary security checks at the memory isolation cell before access requests reach the interconnection matrix. By verifying and filtering addresses in advance, the system prevents security vulnerabilities from arising in the first place rather than reacting to them afterward, maintaining both functionality and security.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9323953B2System for managing secure and nonsecure applications on one and the same microcontroller
Publication Date: 2016.04.26 SCHNEIDER ELECTRIC IND SAS
  • US9323953B2 patent drawing
  • US9323953B2 patent drawing
  • US9323953B2 patent drawing

AI summary

An electronic microcontroller system including: plural processors; at least one interface for exchange with at least one peripheral, the peripheral being user master of the electronic microcontroller system; a mechanism for access to a shared memory space; an interconnection matrix for interconnecting the exchange interface, the processors and the mechanism for access to a shared memory space; a mechanism managing applications involving a guaranteed level of security and integrity and of applications exhibiting a nonguaranteed level of security and integrity. The exchange interface cooperates with a secure isolation cell of the memory situated between the user master peripheral and the interconnection matrix.