Unified Security Environment for Hardware Resource Sharing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Trustzone hardware architecture for computing systems, which uses a single processor core to provide both normal and high security services, suffers from low resource utilization due to frequent switching between security states, resulting in high latency and power consumption.
Innovation Solution
The system groups hardware resources into multiple security levels and assigns user access rights based on the required resources for each request, allowing access to higher levels in the high security state, thereby reducing unnecessary state switching and optimizing resource usage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If the processor frequently switches between normal security state and high security state to increase hardware resource utilization, then resource utilization is improved, but latency and power consumption increase
Solution Approach 1:
The patent merges the normal security environment and high security environment into a single unified environment, eliminating the need for frequent switching between isolated environments. Hardware resources are shared across both security levels through controlled access mechanisms, allowing seamless operation without state transitions while maintaining security boundaries.
Solution Approach 2:
The patent creates a unified security environment where hardware resources serve multiple security levels simultaneously. The same hardware resources can be accessed by both normal security applications and high security applications through the access right checker, making the system multi-functional without requiring dedicated resources for each security level.
2Productivity
If the processor frequently switches between normal security state and high security state to increase hardware resource utilization, then resource utilization is improved, but power consumption increases
Solution Approach 1:
The patent merges the normal security environment and high security environment into a single unified environment, eliminating the need for frequent switching between isolated environments. Hardware resources are shared across both security levels through controlled access mechanisms, allowing seamless operation without state transitions while maintaining security boundaries.
3Reliability
If dedicated hardware resources are assigned to high security environment, then security isolation is improved, but resource utilization decreases
Solution Approach 1:
The patent merges the normal security environment and high security environment into a single unified environment, eliminating the need for frequent switching between isolated environments. Hardware resources are shared across both security levels through controlled access mechanisms, allowing seamless operation without state transitions while maintaining security boundaries.
Solution Approach 2:
The access right checker serves as an intermediary mechanism that controls access to hardware resources based on security levels. It mediates between normal security applications and high security applications, granting appropriate access rights without requiring physical isolation of hardware resources. This intermediary enables secure sharing while maintaining logical security boundaries.
4Device complexity
If a single processor core is used to provide both normal and high security services, then device complexity is reduced, but security isolation becomes challenging
Solution Approach 1:
The patent segments the security model into distinct security levels (normal security level and high security level) that operate within a single processor core. Each security level has defined access rights to hardware resources, creating logical isolation without requiring physical separation. The access right checker enforces these segmented security boundaries.
Solution Approach 2:
The access right checker serves as an intermediary mechanism that controls access to hardware resources based on security levels. It mediates between normal security applications and high security applications, granting appropriate access rights without requiring physical isolation of hardware resources. This intermediary enables secure sharing while maintaining logical security boundaries.
Data Source
AI summary
A computing system and method providing normal security services and high security services are disclosed. The computing system includes hardware resources, a processor core and an access right checker. The hardware resources are grouped into resource security levels. The processor, switching between a normal security and a high security state, assigns a user access right to a request. In comparison with the normal security state, user access right assigned in the high security state further allows the request to use the hardware resources of a higher resource security level. According to the assigned user access right and the resource security levels of required hardware resources of the request, the access right checker determines whether the request has the authority to use the hardware resources, and thereby, the access right checker executes the request or responds the issued request with an exception.


