Sensor Segmentation Access Control for Virtualized SoCs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems on a chip (SoCs) with virtual machines cannot efficiently manage access to sensor data streams from peripherals, leading to replication of peripherals and increased area and power consumption, as they do not allow multiple virtual machines to access the same peripheral simultaneously.

Innovation Solution

A system on a chip (SoC) with a crossbar circuit and queue circuits, where a hypervisor controls queue protection circuits to selectively permit access to digital sensor signals by virtual machines, using status and control registers to manage access permissions and prevent unauthorized access, allowing for multiple virtual machines to access shared peripherals while maintaining isolation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If current systems assign identification numbers to virtual machines and pair them to peripherals on an on-chip network level to permit or deny access, then access control is achieved, but multiple virtual machines cannot access the same peripheral leading to replication of peripherals and increased area and power consumption

Engineering Contradiction:
Improveperipheral sharing capabilityVSAvoidchip area
Core Design Contradiction:
Adaptability or versatilityVSArea of stationary object

Solution Approach 1:

The peripheral is designed to serve multiple virtual machines simultaneously through the hypervisor, which manages access permissions and allows different virtual machines to share the same peripheral resources based on their needs, eliminating the need for peripheral replication

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The hypervisor acts as an intermediary layer between virtual machines and peripherals, controlling access permissions and managing shared peripheral resources, thereby enabling multiple virtual machines to access the same peripheral without direct conflicts

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If current systems assign identification numbers to virtual machines and pair them to peripherals on an on-chip network level to permit or deny access, then access control is achieved, but multiple virtual machines cannot access the same peripheral leading to replication of peripherals and increased power consumption

Engineering Contradiction:
Improveperipheral sharing capabilityVSAvoidpower consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by stationary object

Solution Approach 1:

The peripheral is designed to serve multiple virtual machines simultaneously through the hypervisor, which manages access permissions and allows different virtual machines to share the same peripheral resources based on their needs, eliminating the need for peripheral replication

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Multiple virtual machine access requests are merged into a single shared peripheral instance managed by the hypervisor, consolidating resources and reducing overall power consumption compared to having separate peripheral instances for each virtual machine

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the hypervisor controls queue protection circuits to selectively permit access to digital sensor signals by virtual machines, then secure and isolated access is maintained, but access management complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hypervisor acts as an intermediary layer between virtual machines and peripherals, controlling access permissions and managing shared peripheral resources, thereby enabling multiple virtual machines to access the same peripheral without direct conflicts

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Access control is segmented into queue-level protection circuits that can be independently configured for different virtual machines, allowing fine-grained security control without requiring complex system-wide access management

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11397809B2Protection scheme for sensor segmentation in virtualization application
Publication Date: 2022.07.26 STMICROELECTRONICS INT NV
  • US11397809B2 patent drawing
  • US11397809B2 patent drawing

AI summary

An embedded system includes a peripheral and system-on-a-chip executing virtual machines and a hypervisor. The peripheral includes a crossbar circuit receiving digital sensor signals and selectively outputting the digital sensor signals to different outputs, queue circuits each receiving a different one of the digital sensor signals from the crossbar circuit, and queue protection circuits associated with the queue circuits and selectively permitting access to one of the queue circuits by the virtual machines. The hypervisor controls the queue protection circuits to set which of the virtual machines may access which queue circuits. A sensor protection circuit selectively permits reading of the digital sensor signals from the crossbar circuit by the queue circuits. The hypervisor controls the sensor protection circuit to set which of the queue circuits may access each of the digital sensor signals from the crossbar circuit.