Trust Domain Conversion Bridge for Disparate Memory Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrating disparate circuitry components with different memory and security architectures into a single system poses challenges, as existing technologies lack effective methods to manage disparate memory architectures and security models, limiting the reuse and integration of such components in larger SoCs.

Innovation Solution

The implementation of isolated memory regions (IMRs) and trust domain conversion bridges (TDCBs) allows for the integration of disparate components by providing dynamic memory protection and secure attribute translation across different architectures, enabling consistent memory operations and security without requiring redesign of the components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If disparate circuitry components with different memory and security architectures are integrated into a single system, then component reusability and system functionality are improved, but system complexity and integration difficulty increase

Engineering Contradiction:
Improvecomponent reusabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces isolated memory regions (IMRs) as intermediary structures between disparate circuitry components and the memory system. These IMRs act as mediators that translate between different memory architectures and security models, allowing components with different memory expectations to coexist in a unified system without requiring redesign of the components themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the memory address space into isolated memory regions, each dedicated to specific circuitry components. This segmentation allows different components to have their own memory protection and access control mechanisms independent of each other, while still being managed by a unified memory controller that handles the architectural differences.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If components with different trust domain architectures are integrated, then system functionality and component utilization are improved, but security management and trust domain coordination become more complex

Engineering Contradiction:
Improvecomponent utilizationVSAvoidsecurity architecture complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent employs trust domain conversion bridges as intermediary components that facilitate communication between different trust domains. These bridges translate security attributes and trust domain information between components with different security architectures, enabling secure interaction without requiring all components to conform to a single trust model.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters of memory access and security attributes dynamically based on the trust domain requirements of different components. By adjusting memory protection levels, access permissions, and security attributes in response to component needs, the system maintains security integrity while supporting multiple trust domain architectures.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If flexible memory map components are integrated with fixed memory map components, then system adaptability is improved, but memory protection consistency and architecture compatibility deteriorate

Engineering Contradiction:
Improvememory architecture flexibilityVSAvoidmemory protection consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces isolated memory regions as intermediary structures that bridge flexible and fixed memory map architectures. These IMRs provide a standardized interface that translates between flexible target-based protections and fixed memory map expectations, ensuring consistent memory protection behavior across components with different memory architecture requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates an equipotential memory access environment by providing all components with access to isolated memory regions that enforce uniform protection rules. This ensures that regardless of whether a component expects flexible or fixed memory mapping, the memory protection mechanism remains consistent and reliable across the entire system.

Inventive Principle:
Principle #12Equipotentiality

Data Source

PatentUS12204463B2Integration of disparate system architectures using configurable isolated memory regions and trust domain conversion bridge
Publication Date: 2025.01.21 INTEL CORP
  • US12204463B2 patent drawing
  • US12204463B2 patent drawing
  • US12204463B2 patent drawing

AI summary

Techniques are described for providing consistent memory operations and security across electronic circuitry components having disparate memory and/or security architectures when integrating such disparately architected components within a single system, such as a system on chip. A programmable logical hierarchy of isolated memory region (IMR) enforcement circuits is provided to protect such IMRs, allowing or preventing memory access requests from one of multiple distinct circuitry components based on configuration registers for the IMR enforcement circuits. Integration of multiple trust domain architectures associated with the multiple distinct circuitry components is facilitated via trust domain conversion bridge circuitry that includes translation logic for generating information in accordance with a first trust domain architecture based on information provided in accordance with a distinct second trust domain architecture.