Secure Demand Paging for Processor Memory Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies face challenges in securely handling large amounts of software program code and data in electronic computing and communications systems without requiring substantial additional on-chip memory, especially in wireless communications where security and cost-effectiveness are crucial.
Innovation Solution
A secure demand paging system that includes a processor with internal and external memory, a security circuit, and a microprocessor capable of multi-threading and secure data processing, allowing for secure page configuration, confidentiality, and integrity processing, along with a method for prioritizing page replacement in secure internal memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If secure demand paging is implemented to handle large amounts of software program code and data, then security and memory efficiency are improved, but device complexity increases due to the need for security circuits, multi-threading capabilities, and secure data processing mechanisms
Solution Approach 1:
The patent divides memory into secure internal memory and external memory, separating secure data storage from general storage. The secure demand paging system segments memory management into distinct secure and non-secure operations, allowing security-critical functions to be isolated and managed separately from general-purpose memory operations, thereby improving security without unnecessarily complicating the entire system.
Solution Approach 2:
The processor is designed with multi-threading capability that can handle both secure and non-secure operations simultaneously. The secure demand paging mechanism provides universal memory management functionality that serves both security-critical applications and general-purpose computing needs, reducing the need for separate dedicated security hardware and thereby managing device complexity.
2Quantity of substance
If secure demand paging is implemented to support large applications, then memory efficiency is improved, but manufacturing complexity increases due to the need for integrated security circuits and secure data processing capabilities
Solution Approach 1:
The patent implements secure demand paging as a nested layer of memory management within the existing processor architecture. The secure internal memory is nested within the broader memory hierarchy, with secure paging operations nested within the overall demand paging mechanism. This nested structure allows security functionality to be integrated into existing manufacturing processes rather than requiring completely new manufacturing approaches.
Solution Approach 2:
The secure demand paging system acts as an intermediary layer between the processor and memory systems. It provides secure data processing capabilities through software-based mechanisms that interface with existing hardware, avoiding the need for complex custom security hardware integration and simplifying the manufacturing process while maintaining memory efficiency.
3Reliability
If secure internal memory is used for confidential pages, then confidentiality is improved, but memory capacity is reduced due to the limited size of internal memory
Solution Approach 1:
The patent extends secure memory capacity by adding a temporal and hierarchical dimension to memory management. Confidential pages are stored in secure internal memory when actively needed, while less frequently accessed secure data is moved to external memory. This creates a multi-layered secure memory architecture that provides both confidentiality and increased effective capacity without compromising security.
Solution Approach 2:
The system applies different security and storage characteristics to different portions of memory based on local needs. Confidential pages receive enhanced protection and are stored in secure internal memory, while non-confidential or less sensitive data can be stored in external memory with standard protection. This localized approach to security and storage optimizes both confidentiality and memory capacity utilization.
Data Source
AI summary
A secure demand paging system (1020) includes a processor (1030) operable for executing instructions, an internal memory (1034) for a first page in a first virtual machine context, an external memory (1024) for a second page in a second virtual machine context, and a security circuit (1038) coupled to the processor (1030) and to the internal memory (1034) for maintaining the first page secure in the internal memory (1034). The processor (1030) is operable to execute sets of instructions representing: a central controller (4210), an abort handler (4260) coupled to supply to the central controller (4210) at least one signal representing a page fault by an instruction in the processor (1030), a scavenger (4220) responsive to the central controller (4210) and operable to identify the first page as a page to free, a virtual machine context switcher (4230) responsive to the central controller (4210) to change from the first virtual machine context to the second virtual machine context; and a swapper manager (4240) operable to swap in the second page from the external memory (1024) with decryption and integrity check, to the internal memory (1034) in place of the first page.


