Secure Memory Interface Gating for Multi-Processor Boot and Debug
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing multi-processor devices lack secure and controlled access mechanisms for memory interfaces, particularly during initialization and debug operations, which can compromise security and reliability.
Innovation Solution
A multi-processor device with a secure processor that selectively enables or disables memory access for the primary processor based on the device's operating mode, using cryptographic verification and gating circuitry to manage access, ensuring secure boot-up and debug processes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the primary processor has unrestricted access to the memory interface, then memory access speed and productivity are improved, but security and reliability deteriorate due to unauthorized access during initialization and debug operations
Solution Approach 1:
A secure processor is introduced as an intermediary between the primary processor and the memory interface. The secure processor includes a memory access control unit that mediates all memory access requests, verifying authentication status and controlling access rights. This mediator resolves the contradiction by maintaining high memory access speed for authorized operations while blocking unauthorized access during initialization and debug modes, thus improving security without significantly impacting productivity.
Solution Approach 2:
The memory access control unit dynamically adjusts access permissions based on the operational mode of the multi-processor device. During normal operation, the primary processor has full access for high productivity. During initialization and debug modes, access is restricted to enhance security. This dynamic control resolves the contradiction by adapting access rights to current operational needs, maintaining high productivity during normal operation while ensuring security during critical phases.
2Reliability
If the secure processor controls memory access selectively, then security and reliability are improved, but device complexity increases due to additional control circuitry
Solution Approach 1:
The secure processor is merged with the primary processor on the same chip, combining the security control functions with the existing processor architecture. The memory access control unit is integrated into the secure processor rather than being a completely separate external component. This merging reduces overall device complexity by consolidating functions on a single chip while still providing secure memory access control, resolving the contradiction between security improvement and complexity increase.
Solution Approach 2:
The secure processor performs multiple functions: cryptographic operations, authentication verification, memory access control, and mode management. By making the secure processor multi-functional, the patent reduces the need for separate dedicated control circuitry for each function. This multi-functionality approach resolves the contradiction by achieving comprehensive security control without proportionally increasing device complexity, as one component handles multiple security-related tasks.
3Reliability
If the primary processor is gated from memory access during normal operation, then security is improved by preventing unauthorized access, but productivity deteriorates due to restricted memory access
Solution Approach 1:
The memory access control unit implements dynamic permission management that distinguishes between different operational modes. During normal operation, the primary processor receives full memory access permissions to maintain high productivity. During initialization and debug modes, access permissions are dynamically restricted to enhance security. This dynamic mode-based control resolves the contradiction by ensuring high productivity during normal operation while maintaining security during critical initialization phases, allowing the system to optimize for the appropriate metric at the appropriate time.
Solution Approach 2:
Different quality levels of memory access are provided to different processors based on their role and operational context. The primary processor receives full-quality access during normal operation for maximum productivity. The secure processor receives controlled access for authentication and security functions. During initialization and debug modes, access quality is restricted for security purposes. This local quality differentiation resolves the contradiction by providing full access where needed for productivity while restricting access where security is the priority, optimizing the system for the current operational requirement.
Data Source
AI summary
A multi-processor device is disclosed. The multi-processor device includes memory interface circuitry to access external memory. A primary processor is selectively coupled to the interface circuitry. A secure processor enables/disables access to the memory interface circuitry by the primary processor based on an operating mode of the multi-processor IC chip.


