IP Library › Granted Patent US 12,663,929
Granted Patent B2
US 12,663,929 · App. 18/932,199 · Granted Jun 23, 2026

Dynamic management of a memory firewall

Inventors: Loic Pallardy (Rouillon, FR); Michel Jaouen (Yvre l'Eveque, FR)
Assignee: STMicroelectronics (Grand Ouest) SAS
G06F3/0622G06F3/0655G06F3/0673
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,663,929
App. No.
18/932,199
Filed
Oct 30, 2024
Granted
Jun 23, 2026
Kind
B2
Examiner
LI, ZHUO H
Art Unit
2133
USPC
711/163
Abstract

In embodiments, a system includes a first and a second processing unit, a memory, and a firewall device. The first processing unit operates in a secure mode and generates memory access requests having a secure level. The second processing unit operates in a non-secure mode and generates memory access requests having a non-secure level. The memory includes a first memory area that can be shared between the first and second processing units. The firewall device includes a first firewall circuit with a first configuration authorizing access to the first memory area in the presence of a secure or non-secure level access request. The firewall circuit includes a second configuration prohibiting access to the first memory area in the presence of a secure level access request and authorizing access to the first memory area only in the presence of a non-secure level access request.

Claims (67)

1 . A system, comprising:

a memory storage having a first memory area;

a first processing unit configured to generate memory access requests having a secure level;

a second processing unit configured to generate memory access requests having a non-secure level; and

a firewall device coupled between the memory storage and the first and second processing units, the firewall device comprising a first firewall circuit associated with the first memory area, the first firewall circuit comprising:

a set of registers containing access rights information for the first memory area,

a verification circuit configured to compare security level indications of access requests with the access rights information, and

a configuration interface accessible by the second processing unit,

wherein the first firewall circuit is configurable, via the configuration interface, to operate in:

a first mode authorizing secure and non-secure access requests to the first memory area, and

a second mode authorizing non-secure access requests and prohibiting secure access requests to the first memory area.

2 . The system of claim 1 , wherein the memory storage comprises a memory region allocated to the second processing unit and containing the first memory area.

3 . The system of claim 2 , wherein the memory storage comprises:

a second memory area allocated to the first processing unit; and

a third memory area within the memory region, the third memory area being reserved for the second processing unit.

4 . The system of claim 3 , wherein the firewall device further comprises:

a second firewall circuit associated with the second memory area; and

a third firewall circuit associated with the third memory area,

wherein the second firewall circuit and third firewall circuit each comprise respective registers containing information data representative of secure access rights, non-secure access rights, or a combination thereof, and

wherein the verification circuit is configured to compare security indications with the information data contained in the respective registers.

5 . The system of claim 1 , wherein the configuration interface is coupled to a bus for receiving configuration commands from the second processing unit to modify contents of the set of registers.

6 . The system of claim 1 , wherein each memory access request comprises:

an addressing field for addressing the first memory area; and

a security indication for indicating the secure level or the non-secure level.

7 . The system of claim 1 , wherein the verification circuit comprises logic circuits configured to authorize or prohibit access to the first memory area according to the comparison result.

8 . A method of managing memory access, comprising:

receiving, at a firewall device, an access request for a memory area, the access request having a security level indication;

comparing, by a verification circuit of the firewall device, the security level indication with access rights information stored in a set of registers associated with the memory area;

selectively authorizing or prohibiting the access request based on the comparison and a current configuration mode of the firewall device;

receiving, from a non-secure processing unit, a configuration command at a configuration interface of the firewall device; and

switching the configuration mode of the firewall device between:

a first mode authorizing secure and non-secure access requests to the memory area, and

a second mode authorizing non-secure access requests and prohibiting secure access requests to the memory area.

9 . The method of claim 8 , wherein:

the memory area is within a memory region allocated to the non-secure processing unit; and

the access rights information is stored in the set of registers by the non-secure processing unit.

10 . The method of claim 8 , wherein comparing the security level indication comprises:

comparing, by logic circuits, the security level indication with the access rights information; and

authorizing or prohibiting access according to the comparison result.

11 . The method of claim 8 , further comprising:

receiving a secure level access request at a second firewall circuit associated with a secure memory area;

comparing a security indication of the secure level access request with second access rights information; and

authorizing access to the secure memory area only for secure level access requests.

12 . The method of claim 8 , wherein receiving the configuration command comprises:

receiving the command via a bus interface; and

updating contents of the set of registers based on the command.

13 . The method of claim 8 , wherein the access request comprises:

an addressing field identifying the memory area; and

the security level indication.

14 . The method of claim 8 , wherein switching the configuration mode comprises modifying, via the configuration interface, information data contained in the set of registers.

15 . A firewall device, comprising:

a plurality of firewall circuits, each associated with a respective memory area and comprising:

a set of registers containing access rights information for the associated memory area;

a verification circuit configured to compare security level indications of access requests with the access rights information; and

a configuration interface,

wherein at least a first firewall circuit of the plurality is configurable, via its configuration interface, by a non-secure processing unit to operate in:

a first mode authorizing secure and non-secure access requests to its associated memory area, and

a second mode authorizing non-secure access requests and prohibiting secure access requests to its associated memory area.

16 . The firewall device of claim 15 , wherein the verification circuit comprises logic circuits configured to authorize or prohibit access according to the comparison result, and wherein the configuration interface is coupled to a bus for receiving configuration commands.

17 . The firewall device of claim 15 , wherein the first firewall circuit is associated with a memory area within a memory region allocated to the non-secure processing unit.

18 . The firewall device of claim 15 , wherein the access rights information for each firewall circuit is modifiable via its respective configuration interface.

19 . The firewall device of claim 15 , wherein the verification circuit is configured to:

compare an indication of a request for access with the acess rights information contained in a corresponding set of registers; and

authorize or prohibit access according to the comparison result.

20 . The firewall device of claim 15 , wherein:

a second firewall circuit of the plurality is configured to authorize access only in response to secure level access requests; and

a third firewall circuit of the plurality is configured to authorize access only in response to non-secure level access requests.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 4, 2025
From: PALLARDY, LOIC; JAOUEN, MICHEL
To: STMICROELECTRONICS (GRAND OUEST) SAS
Reel/Frame 070099/0240 →
Priority Claims (1)
FR 2112497 · Nov 25, 2021 · national
Continuity (2)
Continuation 17989389 · Nov 17, 2022
Related Publication 20250053318A1 · Feb 13, 2025
References Cited (46)
US 9342284B2 · Hassanein · 2016 [cited by applicant]
US 10037439B2 · Anderson · 2018 [cited by applicant]
US 10068110B2 · Chun · 2018 [cited by applicant]
US 10587575B2 · Letey · 2020 [cited by applicant]
US 11115383B2 · Mundra · 2021 [cited by applicant]
US 11200345B2 · Lillibridge · 2021 [cited by examiner]
US 12159043B2 · Pallardy · 2024 [cited by examiner]
US 20020078004A1 · Ambrosini et al. · 2002 [cited by applicant]
US 20040039909A1 · Cheng · 2004 [cited by applicant]
US 20050114555A1 · Errickson · 2005 [cited by applicant]
US 20060143411A1 · O'Connor · 2006 [cited by applicant]
US 20070233957A1 · Lev-Ran · 2007 [cited by applicant]
US 20080163359A1 · Conti · 2008 [cited by applicant]
US 20120079590A1 · Sastry · 2012 [cited by applicant]
US 20120239895A1 · Zbiciak · 2012 [cited by applicant]
US 20120272027A1 · Zbiciak · 2012 [cited by applicant]
US 20140115267A1 · Pierson · 2014 [cited by applicant]
US 20140237609A1 · Sharp et al. · 2014 [cited by applicant]
US 20150269396A1 · Grafton · 2015 [cited by applicant]
US 20180121125A1 · Zeng · 2018 [cited by applicant]
US 20180157603A1 · Schulz et al. · 2018 [cited by applicant]
US 20180165226A1 · Krten · 2018 [cited by applicant]
US 20180204024A1 · Lillibridge · 2018 [cited by applicant]
US 20190050558A1 · LeMay et al. · 2019 [cited by applicant]
US 20190332287A1 · Sun · 2019 [cited by applicant]
US 20200036587A1 · Cilfone · 2020 [cited by applicant]
US 20210160134A1 · Anquet et al. · 2021 [cited by applicant]
US 20210232337A1 · Talvitie · 2021 [cited by applicant]
US 20220027520A1 · Li · 2022 [cited by examiner]
US 20230015027A1 · Jaouen · 2023 [cited by examiner]
CN 1723448A · 2006 [cited by applicant]
CN 110678866A · 2020 [cited by applicant]
CN 112119385A · 2020 [cited by applicant]
EP 1563375A1 · 2005 [cited by applicant]
FR 3090923A1 · 2020 [cited by applicant]
FR 3103586A1 · 2021 [cited by applicant]
JP 2006155516A · 2006 [cited by applicant]
WO 2004046924A1 · 2004 [cited by applicant]
WO 2013156315A1 · 2013 [cited by applicant]
WO 2016166450A1 · 2016 [cited by applicant]
WO 2017019061A1 · 2017 [cited by applicant]
Ghosn, Adrien et al., “Enclosure: Language-Based Restriction of Untrusted Libraries”, EPEL & Microsoft Research, Apr. 23, 2021 https:// marioskogias.github.io/docs/enclosure (Year: 2021), pp. 255-267. [cited by applicant]
Hritcu et al., “Secure Compilation,” Sigplan, Jul. 1, 2019, https://blog.sigplan.org/2019/07/01/secure-compilation/ (Year: 2019), 9 pages. [cited by applicant]
Gerstlauer, A., “EE382V System-on-a-Chip (SoC) Design,” Lecture 12—SoC Communication Architectures, University of Texas at Austin, Oct. 17, 2014, 43 pages. [cited by applicant]
Venkateswara Rao, M., et al., “A Frame work on AMBA bus based Communication Architecture to improve the Real Time Computing Performance in MPSoC,” International Journal of Computer Applications (0975-8887), vol. 91, No.… [cited by applicant]
Ezzati, Saeed et al., “A New Method of Hardware Firewall Implementation on SOC,” 2010 International Conference for Internet Technology and Secured Transactions, Nov. 11, 2010, 7 pages. [cited by applicant]