Serial Bus Access Control for Secure and Unsecured Peripherals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems face challenges in efficiently managing shared serial bus communication between secured and unsecured devices, leading to increased bandwidth demand and complex interconnect architectures due to the need for dedicated interconnects for secure communication.
Innovation Solution
Implementing an access control logic in a peripheral controller that manages access to a serial bus, using a multiplexer to select transactions and an access control circuit to enforce policies based on device addresses, allowing secured and unsecured environments to share the bus while ensuring secure transactions are prioritized.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated interconnects are used for secure communication, then security is improved, but device complexity and bandwidth demand increase
Solution Approach 1:
The patent merges secured and unsecured transactions onto a single shared serial bus, eliminating the need for separate dedicated interconnects. The access control logic integrates both security enforcement and transaction routing functions within the existing bus controller, reducing overall system complexity while maintaining security through policy-based access control rather than physical separation.
Solution Approach 2:
The serial bus is designed to serve multiple functions simultaneously - it can handle both secured and unsecured transactions, and can be dynamically allocated to different execution environments based on policy requirements. This multi-functional design replaces multiple dedicated interconnects with a single universal bus that adapts to different security and performance needs.
2Reliability
If dedicated interconnects are used for secure communication, then security is improved, but bandwidth demand increases
Solution Approach 1:
By combining secured and unsecured transactions on a single bus, the system eliminates redundant bandwidth allocation. The shared bus infrastructure serves both security-critical and non-critical traffic, reducing the total bandwidth required compared to having separate dedicated interconnects for secured communication.
Solution Approach 2:
The system applies access control policies selectively rather than treating all transactions uniformly. By allowing unsecured transactions to share the bus with secured ones when security policies permit, the system achieves adequate security protection without the bandwidth overhead of complete isolation, using partial enforcement of security boundaries.
3Ease of operation
If access control logic is implemented in peripheral controller, then ease of operation is improved, but device complexity increases
Solution Approach 1:
The peripheral controller incorporates access control logic that automatically manages bus access rights based on execution environment and transaction type. The controller self-determines whether to allow or block transactions according to configured policies, eliminating the need for external manual access management while maintaining security. This automation simplifies operation despite the added complexity of the control logic.
Data Source
AI summary
A peripheral controller includes a serial engine configured to provide an interface to a serial bus, a multiplexer configured to select between transactions directed to the serial bus and initiated in a plurality of execution environments, and an access control circuit configured to determine when a first transaction to be executed over the serial bus is initiated from a first execution environment, enforce an access policy when the first execution environment is a secured execution environment, determine when a second transaction is initiated from a second execution environment, block the second execution environment and a peripheral device from accessing the serial bus when the first execution environment is accessing the serial bus, and provide the second execution environment and the peripheral device access to the serial bus when the second execution environment is an unsecured execution environment. The access policy may be based on an address of a peripheral device.


