SoC Resource Partitioning Contract for Secure Multi-Owner Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SoC configurations require complex interfaces between multiple semiconductor chips due to mistrust among competing providers, leading to inefficiency and increased complexity in managing resource isolation for safety and security.
Innovation Solution
A system and method for securely sharing resources on a System-on-Chip (SoC) using a partitioning contract (PaCo) and a security engine to authenticate and manage access to resources among multiple owners, ensuring that only authorized code is installed and executed, with encrypted cohort owner tags and cohort authentication tags.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple ECUs are incorporated on separate SoC chips due to mistrust among competing providers, then security and isolation between providers are improved, but device complexity and space consumption increase
Solution Approach 1:
The patent merges multiple provider resources onto a single SoC chip, consolidating what was previously distributed across multiple separate chips. This integration reduces the need for complex external interfaces while maintaining security through virtualization-based isolation mechanisms that allow multiple trusted execution environments to coexist on the same physical hardware.
Solution Approach 2:
The patent segments the single SoC into multiple isolated resource domains, each controlled by a different provider. Through virtualization and trusted execution environments, the system creates logical separation that maintains security isolation equivalent to physical separation, while enabling efficient resource sharing and reduced hardware complexity.
2Productivity
If resources are integrated onto a single SoC controlled by multiple providers, then space efficiency and operational efficiency are improved, but managing isolation and security becomes more complex
Solution Approach 1:
The patent introduces a hypervisor or virtualization layer as an intermediary that manages resource allocation and isolation between multiple providers on the same SoC. This intermediary abstracts the complexity of direct provider-to-provider isolation management, enabling automated enforcement of security policies and simplified coordination while maintaining high operational efficiency.
3Reliability
If separate SoC chips are used for each provider, then trust and security isolation are maintained, but space consumption and interface complexity increase
Solution Approach 1:
The patent combines multiple provider resources onto a single SoC chip, consolidating what was previously distributed across multiple separate chips. This integration reduces the need for complex external interfaces while maintaining security through virtualization-based isolation mechanisms that allow multiple trusted execution environments to coexist on the same physical hardware.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method for protecting access to resources of an SoC among multiple owners. The SoC includes multiple master devices, each configured to conduct transactions with addressed ones of multiple slave devices via an interconnect, multiple access devices coupled to the interconnect and programmed to control access to each slave device, a secure memory that stores a hash value of a partitioning contract incorporating a list of resources available to each of the owners, and a security engine. The security engine is configured to allow installation and execution of code provided by each of the owners only when the code is authenticated by the stored partitioning contract hash value. The security engine is also configured to program the access devices according to the partitioning contract. An encrypted cohort owner tag may be stored for each owner and used to generate cohort authentication tags used to authenticate cohort definitions.