Off-Chip Memory Data Exchange for SoC Security Processors
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing TrustZone architecture in SoCs is vulnerable to unauthorized mode switching by attackers, compromising system security, and the conventional solution of using an email box for information exchange between the application processor and the security processor is inefficient, especially for large data stream services.
Innovation Solution
An integrated chip design that includes an application processor, a security processor, and a storage controller, where data exchange occurs through an off-chip memory, allowing the security processor to read data in an enhanced secure mode and write processed data back to the off-chip memory, improving information exchange efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If an email box (Inbox and Outbox) is used for information exchange between the application processor and the security processor, then data exchange can be achieved, but the storage space is limited and transmission bandwidth is low, resulting in low information exchange efficiency
Solution Approach 1:
The patent transitions from using on-chip email box buffers to using off-chip memory for data exchange. This dimensional change from internal to external storage provides vastly increased storage space and bandwidth capacity, directly resolving the limitation of the email box approach while maintaining the interrupt-based communication mechanism.
2Productivity
If an email box (Inbox and Outbox) is used for information exchange between the application processor and the security processor, then data exchange can be achieved, but the transmission bandwidth is limited, resulting in increased service processing time
Solution Approach 1:
The patent transitions from using on-chip email box buffers to using off-chip memory for data exchange. This dimensional change from internal to external storage provides vastly increased storage space and bandwidth capacity, directly resolving the limitation of the email box approach while maintaining the interrupt-based communication mechanism.
Data Source
AI summary
An integrated chip and a data processing method are provided, to improve system security and service processing efficiency of a system. The integrated chip includes: an application processor, configured to write first data into an off-chip memory in a normal secure mode by using a storage controller, where an address of the first data in the off-chip memory is a first address; a security processor, configured to send a first read instruction to the storage controller in an enhanced secure mode, where the first read instruction is used to request to read the first data at the first address; and the storage controller, configured to control the security processor to read the first data from the off-chip memory.


