Mixed-Criticality Memory Protection Through Security-State Translation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing systems face challenges in effectively isolating and protecting different processes or virtual machines from each other, particularly in scenarios requiring confidential computing, where virtual machines need to be isolated from the hypervisor and other processes to prevent unauthorized access and interference.
Innovation Solution
The implementation of enhanced memory management techniques, including an enhanced region tagging mechanism and configurable access regimes, allows for the creation of additional secure worlds within a processor, enabling efficient translation and protection of memory regions across different criticality levels, using a System-on-a-Chip (SoC) world controller to manage partitioning and access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual machines are isolated from the hypervisor to achieve confidential computing, then security and isolation are improved, but device complexity increases due to additional memory protection mechanisms and access control systems
Solution Approach 1:
The patent segments the memory access control system into multiple independent components: an access control enforcer that evaluates transactions, a translation lookaside buffer for address translation, and a system that supports multiple security states (secure world, non-secure world, supervisor mode). This segmentation allows each component to specialize in specific functions, improving overall security while managing complexity through modular design.
Solution Approach 2:
The access control enforcer acts as an intermediary between the transaction initiator and the memory access. It receives transactions from various security states, evaluates them against defined policies, and determines whether access should be granted. This intermediary layer simplifies the security architecture by centralizing access control logic and reducing the need for complex direct protection mechanisms between all components.
2Reliability
If multiple security states and memory protection mechanisms are implemented to protect sensitive data, then security isolation is improved, but memory management complexity increases
Solution Approach 1:
The access control enforcer serves multiple functions: it translates virtual addresses to physical addresses, evaluates access control policies, determines security state transitions, and manages memory protection across different worlds (secure, non-secure, supervisor). This multi-functionality reduces the need for separate dedicated components for each function, thereby reducing overall memory management complexity while maintaining strong security isolation.
Solution Approach 2:
The system manages different security states by changing parameter values associated with memory access rights and translation behaviors. By defining access control policies as configurable parameters that can be changed based on the current security state, the system achieves flexible security isolation without requiring complex hardwired protection mechanisms for each scenario.
3Reliability
If access control policies are strictly enforced to prevent unauthorized access, then security is improved, but system performance decreases due to additional transaction evaluation overhead
Solution Approach 1:
The system performs preliminary actions by pre-establishing access control policies and security state definitions before actual memory access occurs. The access control enforcer has already evaluated and approved the translation lookaside buffer entries and security state transitions in advance, so that when transactions occur, the evaluation process is streamlined and does not require complex real-time analysis, thus reducing performance impact.
Solution Approach 2:
The translation lookaside buffer and access control enforcer work together in a self-service manner where the buffer automatically provides address translation and the enforcer automatically evaluates policies without requiring external intervention. This automation reduces the computational overhead associated with each transaction evaluation, improving system performance while maintaining strict security enforcement.
Data Source
AI summary
Certain aspects provide a method for processing a transaction. The method generally includes obtaining a transaction indicating a virtual address (VA), and an identifier (ID) for a security state of the transaction initiator, selecting a translation regime based on the ID, determining a physical address (PA) and a PA space (PAS) based on the selected translation regime and the VA, and processing the transaction based on the PA and the PAS.


