Secure Processor Chip Memory Segmentation for Terminal Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intelligent terminal devices prioritize functionality over security, leading to system vulnerabilities that cannot be fully eliminated by software protection means, resulting in ongoing security risks from malicious programs.

Innovation Solution

A processor chip with a memory controller defining a secure area in memory, where the application processor enters a trusted execution environment to access and write data securely, with a communication processor extracting and forwarding data to a secure element, ensuring secure data transfer through secure applications and interrupts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software protection means (firewall or antivirus software) is used to protect against malicious programs, then security protection is provided, but security risks cannot be fully eliminated due to frequent system updates and new virus programs

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the memory into secure memory and non-secure memory, and segments the execution environment into trusted execution environment and non-trusted environment. This segmentation isolates security-critical operations from the complex general-purpose system, providing security without requiring complex software protection mechanisms throughout the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts security-critical functions and data into a separate trusted execution environment with dedicated secure memory. By taking out these critical components from the general-purpose system, the patent provides strong security protection without requiring the entire complex system to be secured, thus resolving the contradiction between security and system complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Adaptability or versatility

If an open and complex system is designed to meet functionality requirements, then functional versatility is improved, but system vulnerabilities increase and security risks cannot be eliminated

Engineering Contradiction:
Improvefunctional requirementsVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by making different parts of the system have different security properties. The trusted execution environment and secure memory have high security quality, while the rest of the system maintains functional versatility. This allows the system to be open and complex for functionality while having localized secure areas that prevent exploitation of system vulnerabilities.

Inventive Principle:
Principle #3Local quality

3Reliability

If the entire system is made secure through software protection, then security is improved, but system complexity and overhead increase significantly

Engineering Contradiction:
Improvesecurity levelVSAvoidprotection mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary trusted execution environment that mediates between the application processor and secure memory. This intermediary provides security protection without requiring complex software protection mechanisms throughout the entire system, thus resolving the contradiction between security level and protection mechanism complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11126753B2Secure processor chip and terminal device
Publication Date: 2021.09.21 HUAWEI TECH CO LTD
  • US11126753B2 patent drawing
  • US11126753B2 patent drawing
  • US11126753B2 patent drawing

AI summary

A processor chip including a memory controller, application processor and a communication processor, where the memory controller is configured to define an area of memory as secure memory, and allow only an access request with a security attribute to access the secure memory. The application processor is configured to invoke a secure application in a trusted execution environment, and write an instruction request for a secure element into the secure memory using the secure application. The communication processor is configured to read the instruction request from the secure memory in the trusted execution environment, and send the instruction request to the secure element. The application processor and the communication processor need to be in the trusted execution environment when accessing the secure memory, and access the secure memory only using the secure application.