Trust Domain Conversion Bridge for Disparate Memory Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrating disparate circuitry components with different memory and security architectures into a single system poses challenges, as existing technologies lack effective methods to manage disparate memory architectures and security models, limiting the reuse and integration of such components in larger SoCs.
Innovation Solution
The implementation of isolated memory regions (IMRs) and trust domain conversion bridges (TDCBs) allows for the integration of disparate components by providing dynamic memory protection and secure attribute translation across different architectures, enabling consistent memory operations and security without requiring redesign of the components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If disparate circuitry components with different memory and security architectures are integrated into a single system, then component reusability and system functionality are improved, but system complexity and integration difficulty increase
Solution Approach 1:
The patent introduces isolated memory regions (IMRs) as intermediary structures between disparate circuitry components and the memory system. These IMRs act as mediators that translate between different memory architectures and security models, allowing components with different memory expectations to coexist in a unified system without requiring redesign of the components themselves.
Solution Approach 2:
The patent segments the memory address space into isolated memory regions, each dedicated to specific circuitry components. This segmentation allows different components to have their own memory protection and access control mechanisms independent of each other, while still being managed by a unified memory controller that handles the architectural differences.
2Adaptability or versatility
If components with different trust domain architectures are integrated, then system functionality and component utilization are improved, but security management and trust domain coordination become more complex
Solution Approach 1:
The patent employs trust domain conversion bridges as intermediary components that facilitate communication between different trust domains. These bridges translate security attributes and trust domain information between components with different security architectures, enabling secure interaction without requiring all components to conform to a single trust model.
Solution Approach 2:
The patent changes the parameters of memory access and security attributes dynamically based on the trust domain requirements of different components. By adjusting memory protection levels, access permissions, and security attributes in response to component needs, the system maintains security integrity while supporting multiple trust domain architectures.
3Adaptability or versatility
If flexible memory map components are integrated with fixed memory map components, then system adaptability is improved, but memory protection consistency and architecture compatibility deteriorate
Solution Approach 1:
The patent introduces isolated memory regions as intermediary structures that bridge flexible and fixed memory map architectures. These IMRs provide a standardized interface that translates between flexible target-based protections and fixed memory map expectations, ensuring consistent memory protection behavior across components with different memory architecture requirements.
Solution Approach 2:
The patent creates an equipotential memory access environment by providing all components with access to isolated memory regions that enforce uniform protection rules. This ensures that regardless of whether a component expects flexible or fixed memory mapping, the memory protection mechanism remains consistent and reliable across the entire system.
Data Source
AI summary
Techniques are described for providing consistent memory operations and security across electronic circuitry components having disparate memory and/or security architectures when integrating such disparately architected components within a single system, such as a system on chip. A programmable logical hierarchy of isolated memory region (IMR) enforcement circuits is provided to protect such IMRs, allowing or preventing memory access requests from one of multiple distinct circuitry components based on configuration registers for the IMR enforcement circuits. Integration of multiple trust domain architectures associated with the multiple distinct circuitry components is facilitated via trust domain conversion bridge circuitry that includes translation logic for generating information in accordance with a first trust domain architecture based on information provided in accordance with a distinct second trust domain architecture.


