Subdivided Memory Domains with Execution-Specific Cache Maintenance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory systems face performance bottlenecks due to unnecessary cache maintenance operations across different domains, leading to inefficiencies and potential data security breaches.

Innovation Solution

Implementing a management execution environment that subdivides domains into variable execution environments, with memory protection circuitry defining a point of encryption and inhibiting maintenance operations to encrypted storage circuits, using domain-specific and execution environment-specific key inputs to secure and optimize cache maintenance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cache maintenance operations are performed across all domains, then data consistency is maintained, but system performance deteriorates due to unnecessary operations

Engineering Contradiction:
Improvedata consistencyVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system divides the domain into multiple execution environments (secure and non-secure) and applies different cache maintenance policies to each. The management execution environment performs maintenance operations only on its own caches and on encrypted storage circuits, while non-secure execution environments are restricted from performing maintenance on encrypted storage. This segmentation eliminates unnecessary maintenance operations across domains while preserving data consistency within each domain.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different cache maintenance policies are applied to different parts of the system based on their security requirements. Encrypted storage circuits receive maintenance operations from the management execution environment, while non-secure execution environments have their maintenance operations restricted. This local differentiation allows the system to maintain data consistency where needed while avoiding performance degradation from unnecessary operations.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If cache maintenance operations are allowed across all execution environments, then operational flexibility is maintained, but data security deteriorates due to potential unauthorized access

Engineering Contradiction:
Improveoperational flexibilityVSAvoidunauthorized access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The management execution environment acts as an intermediary between non-secure execution environments and encrypted storage circuits. It receives cache maintenance requests from non-secure environments, validates them, and forwards only appropriate requests to the encrypted storage. This intermediary mechanism maintains operational flexibility by allowing requests to be made while preventing unauthorized access through validation and filtering.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically determines which execution environments can perform cache maintenance operations based on their security context. The management execution environment has dynamic permission to access encrypted storage, while non-secure environments have restricted permissions. This dynamic permission system maintains flexibility for authorized operations while preventing unauthorized access.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encryption is applied to all storage circuits, then data security is enhanced, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments storage circuits into encrypted and non-encrypted portions, and divides execution environments into management and non-secure categories. This segmentation allows encryption to be applied only where necessary (management environment accessing encrypted storage) while leaving other paths simpler, thereby enhancing security without unnecessarily increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

4Reliability

If domain-specific key inputs are used for encryption, then security is improved, but processing overhead increases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments key management by execution environment, with the management execution environment holding domain-specific keys for encrypted storage. Non-secure environments do not require these keys, eliminating unnecessary cryptographic processing overhead. This selective key usage improves security for protected data while minimizing processing overhead by avoiding unnecessary encryption/decryption operations.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250258779A1Maintenance operations across subdivided memory domains
Publication Date: 2025.08.14 ARM LTD
  • US20250258779A1 patent drawing
  • US20250258779A1 patent drawing
  • US20250258779A1 patent drawing

AI summary

An apparatus is provided in which processing circuitry performs processing in one of a fixed number of at least two domains. One of the domains is subdivided into a variable number of execution environments one of which is a management execution environment configured to manage the execution environments. Memory protection circuitry defines a point of encryption after at least one unencrypted storage circuit of a memory hierarchy and before at least one encrypted storage circuit of the memory hierarchy. The at least one encrypted storage circuitry uses a key input to perform encryption or decryption on the data of a memory access request issued from within a current one of the domains. The key input is different for each of the domains and for each of the execution environments and the management execution environment is configured to inhibit issuing a maintenance operation to the at least one encrypted storage circuit of the memory hierarchy.