Target Firewall Data Structures for SoC Memory Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile devices face security challenges in implementing secure modes for e-commerce and m-commerce due to vulnerabilities in operating systems, which can be exploited by malicious software, and there is a need to prevent unauthorized access to secure memory components.

Innovation Solution

A system-on-chip (SoC) architecture with initiator and target memory components, where each target firewall is programmed with access conditions, compares qualifiers from initiator components to determine legal access, and signals a system security controller to take protective action if access conditions are not met, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a higher level of privilege is provided for secure mode operations, then security for e-commerce and m-commerce is improved, but the system becomes vulnerable to operating system vulnerabilities and malicious software attacks

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to malicious software
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the system into distinct privilege levels (secure mode and non-secure mode) with separate execution environments. The secure mode operates with restricted access to system resources and is isolated from the non-secure operating system, thereby preventing OS vulnerabilities from affecting secure operations while maintaining high security standards.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a third level of privilege (secure mode) is implemented with hardware-based monitoring, then security against OS vulnerabilities is improved, but the device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidhardware-based monitoring structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a firewall as an intermediary component between the secure mode and non-secure mode. This firewall acts as a mediator that controls and filters all communications and access requests between the two modes, simplifying the hardware monitoring structure by providing a single point of control rather than complex distributed monitoring across multiple components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If firewalls are programmed with data structures indicating access conditions for each initiator component, then unauthorized access prevention is improved, but the programming and configuration complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidfirewall programming complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-programming the firewall with comprehensive access control data structures during system initialization or manufacturing. These data structures contain all necessary access conditions, permissions, and restrictions for each initiator component, allowing the firewall to automatically enforce security policies without requiring complex real-time programming decisions, thereby reducing operational complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8307416B2Data structures for use in firewalls
Publication Date: 2012.11.06 TEXAS INSTRUMENTS INC
  • US8307416B2 patent drawing
  • US8307416B2 patent drawing
  • US8307416B2 patent drawing

AI summary

A system-on-chip (SOC) that includes a plurality of initiator components, and a target memory component coupled to the initiator components and having a target firewall, wherein the target firewall is configured to be programmed with a data structure which indicates, for at least one portion of the target memory component, access conditions for each initiator component.