Processor Diagnostic Data Capture Control for Multi-Domain Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Monitoring processors that operate in multiple domains, such as secure and non-secure domains, face challenges in detecting faults while preventing data leakage between these domains, as comprehensive monitoring access can compromise security but limited access hinders fault detection.
Innovation Solution
A processor with monitoring logic and control logic that suppresses diagnostic data capture in specific domains or modes based on control parameters, allowing for selective monitoring to balance fault detection and security by identifying and controlling access to sensitive information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If comprehensive monitoring access is provided to the entire processor, then fault detection capability is improved, but security is worsened due to potential data leakage between domains
Solution Approach 1:
The patent applies local quality by making the monitoring access domain-specific. Different monitoring rules are applied to different domains: full monitoring access is granted to the non-secure domain while the secure domain has restricted access. This is implemented through domain identification logic that checks which domain is currently active and selectively enables or disables monitoring capture based on the domain, thereby allowing comprehensive fault detection in non-secure areas while protecting secure areas from data leakage.
2Object-affected harmful factors
If monitoring access is restricted to certain domains, then security is improved, but fault detection capability is worsened
Solution Approach 1:
The patent applies dynamics by making the monitoring access configuration changeable at runtime. The system includes configuration registers that allow the monitoring behavior to be dynamically adjusted based on the operational context. When the processor is operating in the secure domain, monitoring is automatically suppressed; when operating in the non-secure domain, monitoring is enabled. This dynamic adaptation allows the system to optimize both security and fault detection capability depending on the current domain of operation.
3Object-affected harmful factors
If monitoring functions are completely disabled in a domain, then data leakage is prevented, but the ability to locate faults in that domain is lost
Solution Approach 1:
The patent applies segmentation by dividing the monitoring function into domain-specific segments. Instead of a single unified monitoring mechanism, the system creates separate monitoring paths for secure and non-secure domains. The secure domain segment has monitoring disabled to prevent data leakage, while the non-secure domain segment has monitoring enabled for fault detection. This segmentation allows each domain to have optimized monitoring behavior appropriate to its security requirements.
Data Source
AI summary
There is provided a processor operable in a first domain and a second domain, the processor comprising: monitoring logic operable to monitor the processor and capture diagnostic data; a storage element operable to contain at least one control parameter; control logic operable to control the monitoring logic in dependence on the at least one control parameter and the domain in which the processor is operating, to suppress capturing of diagnostic data relating to predetermined activities of the processor in the first domain. In some embodiments the first domain is a secure domain and the second domain is a non-secure domain, the monitoring function being debug or trace.


