Processor Privilege Mode Emulator for Memory Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional processor systems lack built-in privilege modes to limit access to memory circuits and registers, compromising security and data protection.

Innovation Solution

Implementing a processor system with a vector relocator, privilege mode emulator, and protection modes that include a boot state, open mode, protected mode, and kill mode, using programmable logic circuits and memory types like flash and ROM to restrict access and ensure data security through protection policies and vector relocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional processor systems operate without built-in privilege modes, then the system structure remains simple and ease of manufacture is maintained, but security and data protection are compromised

Engineering Contradiction:
Improvedata protectionVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is segmented into multiple operational modes (boot mode, open mode, protected mode, kill mode) with distinct access privileges. Each mode segments the access rights to memory circuits and registers, allowing the processor to operate with different levels of protection depending on the current state, thereby improving data protection without requiring complete structural redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A privilege mode emulator is introduced as an intermediary component that mediates access between the processor and memory circuits/registers. This emulator enforces protection policies by intercepting and controlling access requests, enabling secure operation without fundamentally altering the core processor architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access to memory circuits and registers is restricted through protection modes, then data integrity is improved, but access flexibility and ease of operation deteriorate

Engineering Contradiction:
Improvedata integrityVSAvoidaccess flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system dynamically transitions between different protection modes (boot → open → protected → kill) based on operational requirements. Access flexibility is maintained during boot and open modes when full access is needed, while data integrity is enforced during protected mode. The system adapts its access control characteristics dynamically rather than being statically restricted.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The protection level parameter is changed by transitioning between operational modes. Each mode represents a different state of the protection parameter, allowing the system to adjust its access control characteristics as needed. This enables the system to maintain ease of operation when high access flexibility is required while ensuring data integrity when protection is prioritized.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If privilege mode emulator and vector relocator are implemented, then security against unauthorized access is improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
ImprovesecurityVSAvoidmanufacturing difficulty
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The privilege mode emulator and vector relocator are designed as multi-functional components that handle multiple security-related tasks. The emulator not only controls access to memory circuits but also manages transitions between protection modes and coordinates with the vector relocator. This consolidation of multiple security functions into unified components reduces the overall number of discrete elements required, thereby mitigating manufacturing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9262340B1Privileged mode methods and circuits for processor systems
Publication Date: 2016.02.16 INFINEON TECHNOLOGIES AMERICAS CORP
  • US9262340B1 patent drawing
  • US9262340B1 patent drawing
  • US9262340B1 patent drawing

AI summary

A system can include a processor coupled to a bus; a first memory coupled to the bus, configured to limit access to a privileged portion according to at least protection values; a second memory coupled to the bus and having a privileged supervisory portion configured to be section erasable, access to the second memory being limited according to at least the protection values; and a boot sequence stored in the privileged portion that configures the processor to decode values stored in the supervisory portion into the protection values for storage in protection value registers.