Target Firewall Data Structures for SoC Memory Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile devices face security challenges in implementing secure modes for e-commerce and m-commerce due to vulnerabilities in operating systems, which can be exploited by malicious software, and there is a need to prevent unauthorized access to secure memory components.
Innovation Solution
A system-on-chip (SoC) architecture with initiator and target memory components, where each target firewall is programmed with access conditions, compares qualifiers from initiator components to determine legal access, and signals a system security controller to take protective action if access conditions are not met, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a higher level of privilege is provided for secure mode operations, then security for e-commerce and m-commerce is improved, but the system becomes vulnerable to operating system vulnerabilities and malicious software attacks
Solution Approach 1:
The patent segments the system into distinct privilege levels (secure mode and non-secure mode) with separate execution environments. The secure mode operates with restricted access to system resources and is isolated from the non-secure operating system, thereby preventing OS vulnerabilities from affecting secure operations while maintaining high security standards.
2Reliability
If a third level of privilege (secure mode) is implemented with hardware-based monitoring, then security against OS vulnerabilities is improved, but the device complexity increases
Solution Approach 1:
The patent introduces a firewall as an intermediary component between the secure mode and non-secure mode. This firewall acts as a mediator that controls and filters all communications and access requests between the two modes, simplifying the hardware monitoring structure by providing a single point of control rather than complex distributed monitoring across multiple components.
3Reliability
If firewalls are programmed with data structures indicating access conditions for each initiator component, then unauthorized access prevention is improved, but the programming and configuration complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-programming the firewall with comprehensive access control data structures during system initialization or manufacturing. These data structures contain all necessary access conditions, permissions, and restrictions for each initiator component, allowing the firewall to automatically enforce security policies without requiring complex real-time programming decisions, thereby reducing operational complexity.
Data Source
AI summary
A system-on-chip (SOC) that includes a plurality of initiator components, and a target memory component coupled to the initiator components and having a target firewall, wherein the target firewall is configured to be programmed with a data structure which indicates, for at least one portion of the target memory component, access conditions for each initiator component.


