Unified Security Environment for Hardware Resource Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing Trustzone hardware architecture for computing systems, which uses a single processor core to provide both normal and high security services, suffers from low resource utilization due to frequent switching between security states, resulting in high latency and power consumption.

Innovation Solution

The system groups hardware resources into multiple security levels and assigns user access rights based on the required resources for each request, allowing access to higher levels in the high security state, thereby reducing unnecessary state switching and optimizing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the processor frequently switches between normal security state and high security state to increase hardware resource utilization, then resource utilization is improved, but latency and power consumption increase

Engineering Contradiction:
Improvehardware resource utilizationVSAvoidswitching latency
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent merges the normal security environment and high security environment into a single unified environment, eliminating the need for frequent switching between isolated environments. Hardware resources are shared across both security levels through controlled access mechanisms, allowing seamless operation without state transitions while maintaining security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a unified security environment where hardware resources serve multiple security levels simultaneously. The same hardware resources can be accessed by both normal security applications and high security applications through the access right checker, making the system multi-functional without requiring dedicated resources for each security level.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If the processor frequently switches between normal security state and high security state to increase hardware resource utilization, then resource utilization is improved, but power consumption increases

Engineering Contradiction:
Improvehardware resource utilizationVSAvoidpower consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent merges the normal security environment and high security environment into a single unified environment, eliminating the need for frequent switching between isolated environments. Hardware resources are shared across both security levels through controlled access mechanisms, allowing seamless operation without state transitions while maintaining security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If dedicated hardware resources are assigned to high security environment, then security isolation is improved, but resource utilization decreases

Engineering Contradiction:
Improvesecurity isolationVSAvoidresource utilization
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent merges the normal security environment and high security environment into a single unified environment, eliminating the need for frequent switching between isolated environments. Hardware resources are shared across both security levels through controlled access mechanisms, allowing seamless operation without state transitions while maintaining security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access right checker serves as an intermediary mechanism that controls access to hardware resources based on security levels. It mediates between normal security applications and high security applications, granting appropriate access rights without requiring physical isolation of hardware resources. This intermediary enables secure sharing while maintaining logical security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Device complexity

If a single processor core is used to provide both normal and high security services, then device complexity is reduced, but security isolation becomes challenging

Engineering Contradiction:
Improveprocessor core countVSAvoidsecurity isolation
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security model into distinct security levels (normal security level and high security level) that operate within a single processor core. Each security level has defined access rights to hardware resources, creating logical isolation without requiring physical separation. The access right checker enforces these segmented security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The access right checker serves as an intermediary mechanism that controls access to hardware resources based on security levels. It mediates between normal security applications and high security applications, granting appropriate access rights without requiring physical isolation of hardware resources. This intermediary enables secure sharing while maintaining logical security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8407783B2Computing system providing normal security and high security services
Publication Date: 2013.03.26 HAMILCAR BARCA IP LLC
  • US8407783B2 patent drawing
  • US8407783B2 patent drawing
  • US8407783B2 patent drawing

AI summary

A computing system and method providing normal security services and high security services are disclosed. The computing system includes hardware resources, a processor core and an access right checker. The hardware resources are grouped into resource security levels. The processor, switching between a normal security and a high security state, assigns a user access right to a request. In comparison with the normal security state, user access right assigned in the high security state further allows the request to use the hardware resources of a higher resource security level. According to the assigned user access right and the resource security levels of required hardware resources of the request, the access right checker determines whether the request has the authority to use the hardware resources, and thereby, the access right checker executes the request or responds the issued request with an exception.