Privilege-Based Access Control for Shared Bus Peripherals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In multicore processing systems, existing shared bus architectures face challenges in managing access to system peripherals, leading to potential resource conflicts and inefficiencies, particularly in ensuring secure access and optimal resource utilization.

Innovation Solution

Implementing access control logic based on privilege levels to dynamically allocate and re-allocate shared peripherals among processing cores, using a global system configuration register and controller identifiers to manage access and prevent unauthorized modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a shared bus architecture is used to connect multiple processing cores to system peripherals, then resource utilization and system efficiency are improved, but access conflicts and security risks arise when multiple cores attempt to modify critical peripherals simultaneously

Engineering Contradiction:
Improveresource utilizationVSAvoidaccess security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic access control where the shared bus controller can change the operational state of peripherals in real-time based on core privilege levels and current system conditions. The controller dynamically switches between shared access mode and exclusive access mode, allowing flexible resource allocation while maintaining security. This dynamic approach enables the system to adapt access permissions on-the-fly without requiring static configuration or physical isolation of peripherals.

Inventive Principle:
Principle #15Dynamics

2Reliability

If private buses are used for system peripherals to avoid resource conflicts, then access security and reliability are improved, but device complexity and die area increase due to duplication of peripheral modules

Engineering Contradiction:
Improveaccess securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a shared bus controller as an intermediary between processing cores and system peripherals. This controller acts as a smart mediator that manages all access requests, enforces security policies, and coordinates simultaneous access needs. By placing this intelligent intermediary in the data path, the system maintains a shared bus architecture while achieving security levels previously only possible with private buses. The controller mediates conflicts by granting exclusive access to authorized cores while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If any processing core can access shared peripherals without restriction, then ease of operation and flexibility are improved, but unauthorized modifications and system instability occur

Engineering Contradiction:
Improveaccess flexibilityVSAvoidunauthorized modifications
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different access control policies to different peripherals based on their criticality and security requirements. The shared bus controller evaluates each access request individually, considering the target peripheral's security attributes and the requesting core's privilege level. This local quality approach means that critical peripherals receive strict access control while less sensitive peripherals maintain broader accessibility. The system thus provides tailored access control rather than a one-size-fits-all approach, optimizing both security and operational flexibility for each specific peripheral.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240152658A1Systems and methods for access protection of system peripherals
Publication Date: 2024.05.09 CIRRUS LOGIC INT SEMICON LTD
  • US20240152658A1 patent drawing
  • US20240152658A1 patent drawing

AI summary

A system may include a plurality of processing cores, a target shared among the plurality of processing cores and coupled to the plurality of processing cores via a shared bus, and access control logic configured to, based on access configuration settings associated with the target, control access of requests from each of the plurality of processing cores based on a privilege level of each of the plurality of processing cores, in order to dynamically allocate and re-allocate the target among the plurality of processing cores in accordance with the privilege levels and to dynamically utilize the target in accordance with the privilege levels.