VM Address Conversion for Secure Switch Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional hardware control systems for virtual machines fail to securely manage switch permissions, leading to information security loopholes as expectantly disabled function circuits are inadvertently enabled.

Innovation Solution

A hardware control method and system utilizing extended physical addresses to ensure that only one switch is activated by the operating system's control command, while keeping other switches disabled, by converting virtual addresses to intermediate and then extended physical addresses, and determining switch statuses to control function circuits accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a converting circuit uses one page size as a unit for address conversion when controlling switches with virtual machines, then the address conversion process is simplified, but expectantly disabled switches are inadvertently enabled causing information security loopholes

Engineering Contradiction:
Improveaddress conversion processVSAvoidinformation security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the address conversion process into multiple distinct stages: virtual address to intermediate address conversion, intermediate address to extended physical address conversion, and extended physical address to hardware physical address conversion. This segmentation allows precise control at each stage, enabling the system to activate only specific switches corresponding to permitted function circuits while keeping other switches disabled, thus resolving the security issue without excessive complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediate addresses and extended physical addresses as intermediary layers between the virtual address and the final hardware physical address. These intermediary layers act as mediators that enable fine-grained control over switch activation, allowing the system to precisely enable only the intended switch while preventing unintended switches from being activated, thereby maintaining information security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple switches are controlled simultaneously through address conversion, then the control efficiency is improved, but the precision of switch permission control is reduced

Engineering Contradiction:
Improvecontrol efficiencyVSAvoidswitch permission control precision
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent divides the control process into multiple sequential conversion stages, where each stage processes address components independently. This segmentation enables the system to maintain high control efficiency by processing multiple switches through the same conversion pipeline while achieving precise permission control by applying different conversion rules at each stage based on the specific switch and operating system permissions

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different conversion rules and properties to different parts of the address space. Specifically, the conversion process adapts its behavior based on the intermediate address value, applying different transformation rules to ensure that only the intended switch is activated while maintaining efficient batch processing capabilities for multiple switches

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10698720B2Hardware control method and hardware control system
Publication Date: 2020.06.30 MEDIATEK INC
  • US10698720B2 patent drawing
  • US10698720B2 patent drawing
  • US10698720B2 patent drawing

AI summary

A hardware control method and a hardware control system. The hardware control method is for an operating system to control at least one function circuit. The hardware control method includes: converting a first virtual address and a second virtual address from the operating system to a first intermediate address and a second intermediate address, respectively; converting the first intermediate address and the second intermediate address to a first extended physical address and a second extended physical address, respectively, wherein a starting position of the first extended physical address is distanced by a gap from a starting position of the second extended physical address; and converting the first extended physical address and the second extended physical address to a first hardware physical address and a second hardware physical address, respectively, wherein the first hardware physical address is adjacent to the second hardware physical address.