SoC Resource Partitioning Contract for Secure Multi-Owner Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SoC configurations require complex interfaces between multiple semiconductor chips due to mistrust among competing providers, leading to inefficiency and increased complexity in managing resource isolation for safety and security.

Innovation Solution

A system and method for securely sharing resources on a System-on-Chip (SoC) using a partitioning contract (PaCo) and a security engine to authenticate and manage access to resources among multiple owners, ensuring that only authorized code is installed and executed, with encrypted cohort owner tags and cohort authentication tags.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple ECUs are incorporated on separate SoC chips due to mistrust among competing providers, then security and isolation between providers are improved, but device complexity and space consumption increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidcomplex interfaces between multiple SoC chips
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple provider resources onto a single SoC chip, consolidating what was previously distributed across multiple separate chips. This integration reduces the need for complex external interfaces while maintaining security through virtualization-based isolation mechanisms that allow multiple trusted execution environments to coexist on the same physical hardware.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the single SoC into multiple isolated resource domains, each controlled by a different provider. Through virtualization and trusted execution environments, the system creates logical separation that maintains security isolation equivalent to physical separation, while enabling efficient resource sharing and reduced hardware complexity.

Inventive Principle:
Principle #1Segmentation

2Productivity

If resources are integrated onto a single SoC controlled by multiple providers, then space efficiency and operational efficiency are improved, but managing isolation and security becomes more complex

Engineering Contradiction:
Improveoperational efficiencyVSAvoidcomplexity of managing isolation
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a hypervisor or virtualization layer as an intermediary that manages resource allocation and isolation between multiple providers on the same SoC. This intermediary abstracts the complexity of direct provider-to-provider isolation management, enabling automated enforcement of security policies and simplified coordination while maintaining high operational efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate SoC chips are used for each provider, then trust and security isolation are maintained, but space consumption and interface complexity increase

Engineering Contradiction:
Improvetrust among providersVSAvoidspace consumption
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent combines multiple provider resources onto a single SoC chip, consolidating what was previously distributed across multiple separate chips. This integration reduces the need for complex external interfaces while maintaining security through virtualization-based isolation mechanisms that allow multiple trusted execution environments to coexist on the same physical hardware.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP4664328A1System and method of sharing resources on a system on chip in a secure manner
Publication Date: 2025.12.17 NXP USA INC
  • EP4664328A1 patent drawingFigure 1
  • EP4664328A1 patent drawingFigure 2
  • EP4664328A1 patent drawingFigure 3

AI summary

A system and method for protecting access to resources of an SoC among multiple owners. The SoC includes multiple master devices, each configured to conduct transactions with addressed ones of multiple slave devices via an interconnect, multiple access devices coupled to the interconnect and programmed to control access to each slave device, a secure memory that stores a hash value of a partitioning contract incorporating a list of resources available to each of the owners, and a security engine. The security engine is configured to allow installation and execution of code provided by each of the owners only when the code is authenticated by the stored partitioning contract hash value. The security engine is also configured to program the access devices according to the partitioning contract. An encrypted cohort owner tag may be stored for each owner and used to generate cohort authentication tags used to authenticate cohort definitions.