SoC Access Control Unit Group-Based Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current system-on-chip (SoC) technologies face challenges in protecting hardware blocks due to the high cost and coarse granularity of address range-based protection schemes, which are inadequate for fine-grained protection of registers and compatibility with existing address-based memory protection capabilities.
Innovation Solution
A system-on-chip with an access control unit and protection unit that utilize an authorization list and group assignment to evaluate access requests, allowing for fine-grained protection of responder elements by assigning groups with specific access requirements, reducing the need for multiple address ranges and improving protection granularity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If address range-based protection schemes are used to protect hardware blocks, then protection capability is provided, but hardware complexity and cost increase significantly
Solution Approach 1:
The hardware block is segmented into multiple groups, where each group can be independently protected. This segmentation allows the protection mechanism to operate on a finer granularity level, reducing the need for multiple address ranges and associated hardware resources while maintaining comprehensive protection coverage.
Solution Approach 2:
The protection mechanism changes the parameter of protection granularity from coarse address-range level to fine group level. By introducing group identifiers and modifying how protection domains are defined, the system achieves finer protection without proportionally increasing hardware complexity.
2Measurement precision
If address range-based protection is implemented with fine granularity to protect individual registers, then protection precision improves, but the number of required address ranges and hardware resources increases
Solution Approach 1:
The hardware block is divided into multiple protectable groups, each with its own group identifier. This segmentation enables fine-grained protection of individual registers or small groups of registers without requiring a separate address range for each, thereby reducing the total number of address ranges needed while achieving the desired protection precision.
Solution Approach 2:
The group-based protection mechanism serves multiple functions: it provides fine-grained protection, reduces the number of address ranges required, and maintains compatibility with existing address-based memory protection. A single group identifier can protect multiple registers, making the protection mechanism more universal and efficient.
3Adaptability or versatility
If hardware-assisted virtualization with address range protection is used, then virtualization capability is enabled, but the cost of protection hardware and timing path complexity increase
Solution Approach 1:
By segmenting the hardware block into groups with unique identifiers, the system enables virtualization capability without requiring complex address range protection for each virtual machine. The group-based approach simplifies the protection hardware while maintaining the ability to isolate and protect resources for multiple virtual machines.
Solution Approach 2:
Instead of implementing complex address range checking hardware for each virtual machine, the system uses group identifiers that can be copied and compared against protection domains. This copying approach simplifies the hardware implementation while maintaining virtualization capabilities.
Data Source
AI summary
A system on chip comprises a responder unit comprising a set of responder elements and an access control unit associated with an authorization list and the responder unit. An entry of the authorization list defines a set of access requirements in relation to an address space identifying at least part of the responder unit. The access control unit is arranged to: receive a request for access to a target responder element among the responder elements of the responder unit, determine the corresponding set of access requirements for the received access request from the authorization list, and evaluate the request for access with respect to the determined set of access requirements and generate a first request evaluation result. A protection unit associated with the responder unit is arranged to: provide a group assignment assigning a group to each of the responder elements of the responder unit, provide a group authorization list, an entry of the group authorization list defining a set of group access requirements for the group assigned, receive the request for access to the target responder element, determine the group assigned to the target responder element from the group assignment and further determine the set of group access requirements from the group authorization list for the group assigned. The system-on-chip also evaluates the request with respect to the determined set of group access requirements and generates a second request evaluation result. Interaction with the target responder element is controlled in response to the first and/or second evaluation result.


