Serial Bus Access Control for Secure and Unsecured Peripherals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems face challenges in efficiently managing shared serial bus communication between secured and unsecured devices, leading to increased bandwidth demand and complex interconnect architectures due to the need for dedicated interconnects for secure communication.

Innovation Solution

Implementing an access control logic in a peripheral controller that manages access to a serial bus, using a multiplexer to select transactions and an access control circuit to enforce policies based on device addresses, allowing secured and unsecured environments to share the bus while ensuring secure transactions are prioritized.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated interconnects are used for secure communication, then security is improved, but device complexity and bandwidth demand increase

Engineering Contradiction:
ImprovesecurityVSAvoidinterconnect architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges secured and unsecured transactions onto a single shared serial bus, eliminating the need for separate dedicated interconnects. The access control logic integrates both security enforcement and transaction routing functions within the existing bus controller, reducing overall system complexity while maintaining security through policy-based access control rather than physical separation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The serial bus is designed to serve multiple functions simultaneously - it can handle both secured and unsecured transactions, and can be dynamically allocated to different execution environments based on policy requirements. This multi-functional design replaces multiple dedicated interconnects with a single universal bus that adapts to different security and performance needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If dedicated interconnects are used for secure communication, then security is improved, but bandwidth demand increases

Engineering Contradiction:
ImprovesecurityVSAvoidbandwidth
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

By combining secured and unsecured transactions on a single bus, the system eliminates redundant bandwidth allocation. The shared bus infrastructure serves both security-critical and non-critical traffic, reducing the total bandwidth required compared to having separate dedicated interconnects for secured communication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system applies access control policies selectively rather than treating all transactions uniformly. By allowing unsecured transactions to share the bus with secured ones when security policies permit, the system achieves adequate security protection without the bandwidth overhead of complete isolation, using partial enforcement of security boundaries.

Inventive Principle:
Principle #16Partial or excessive action

3Ease of operation

If access control logic is implemented in peripheral controller, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveaccess managementVSAvoidcontroller architecture
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The peripheral controller incorporates access control logic that automatically manages bus access rights based on execution environment and transaction type. The controller self-determines whether to allow or block transactions according to configured policies, eliminating the need for external manual access management while maintaining security. This automation simplifies operation despite the added complexity of the control logic.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12468825B2Sharing and protecting secured subordinate devices on an unsecured bus
Publication Date: 2025.11.11 QUALCOMM INC
  • US12468825B2 patent drawing
  • US12468825B2 patent drawing
  • US12468825B2 patent drawing

AI summary

A peripheral controller includes a serial engine configured to provide an interface to a serial bus, a multiplexer configured to select between transactions directed to the serial bus and initiated in a plurality of execution environments, and an access control circuit configured to determine when a first transaction to be executed over the serial bus is initiated from a first execution environment, enforce an access policy when the first execution environment is a secured execution environment, determine when a second transaction is initiated from a second execution environment, block the second execution environment and a peripheral device from accessing the serial bus when the first execution environment is accessing the serial bus, and provide the second execution environment and the peripheral device access to the serial bus when the second execution environment is an unsecured execution environment. The access policy may be based on an address of a peripheral device.