Processor Memory Access Protection via APRs and LINKs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current systems fail to effectively isolate and protect higher safety level functions from faults or attacks in lower safety level functions, and do not securely manage separate execution environments with different security requirements, leading to potential interference and breaches.
Innovation Solution
A circuit device with a processor and memory that uses access protection registers (APRs) and LINKs to determine memory access permissions, creating permissions association trees that enforce safety and security policies, allowing only authorized access and execution across different memory ranges and execution contexts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software configuration processes are used for context switching with firewall configuration, then security management between different execution environments is achieved, but the process complexity and time consumption increase significantly
Solution Approach 1:
The patent replaces software-based firewall configuration and context switching mechanisms with hardware-enforced memory access control. The memory protection unit and access protection registers provide automatic hardware-level permission checking, eliminating the need for complex software configuration processes while maintaining security isolation between execution environments.
Solution Approach 2:
The patent introduces a memory protection unit as an intermediary component between the processor and memory system. This unit contains access protection registers that automatically enforce permission policies, serving as a hardware mediator that simplifies security management without requiring complex software intervention for context switching.
2Productivity
If real-time processing with fast response times is implemented, then productivity is improved, but the time available for context switching and security configuration is reduced
Solution Approach 1:
The patent replaces software-based security configuration processes with hardware-enforced access control. The memory protection unit automatically checks permissions at the hardware level during context switching, eliminating time-consuming software configuration steps and enabling faster real-time processing with reduced context switching overhead.
3Reliability
If separate execution environments are implemented for different security levels, then security isolation is improved, but the device complexity and memory management overhead increase
Solution Approach 1:
The patent segments memory into distinct ranges with independently configurable access protection registers. Each memory range can be assigned to different execution environments with specific permission policies, providing hardware-enforced security isolation while maintaining organized and manageable memory structure through the memory protection unit.
Solution Approach 2:
The memory protection unit serves multiple functions: it manages separate execution environments, enforces security policies, controls context switching, and provides permission checking for different memory ranges. This universal hardware component simplifies overall system complexity by consolidating security management functions in a single unit.
Data Source
AI summary
In described examples, a circuit device includes a memory having a set of memory ranges and a processor device coupled to the memory. The processor device is configured to fetch programmable instructions from the memory, and configured to determine memory access and execution permissions for the programmable instructions. Permissions are determined responsive to a set of a set of access protection registers (APRs) and a set of LINKs. The APRs each specify permissions for a respective associated memory range. The LINKs are each associated with a respective subset of the APRs. Each of the APRs specifies access protection responsive to each LINK. Each of the programmable instructions corresponds to the APR (source APR) associated with a memory range in which the programmable instruction is stored, and corresponds to the LINK (source LINK) associated with the respective source APR.


