<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ep-patent-document PUBLIC "-//EPO//EP PATENT DOCUMENT 1.4//EN" "ep-patent-document-v1-4.dtd">
<ep-patent-document id="EP06114732B9W1" file="EP06114732W1B9.xml" lang="en" country="EP" doc-number="1862908" kind="B9" correction-code="W1" date-publ="20100804" status="c" dtd-version="ep-patent-document-v1-4">
<SDOBI lang="en"><B000><eptags><B001EP>......DE....FRGB....................................................................................</B001EP><B005EP>J</B005EP><B007EP>DIM360 Ver 2.15 (14 Jul 2008) -  2999001/0</B007EP><B078EP><date>20100517</date></B078EP></eptags></B000><B100><B110>1862908</B110><B120><B121>CORRECTED EUROPEAN PATENT SPECIFICATION</B121></B120><B130>B9</B130><B132EP>B1</B132EP><B140><date>20100804</date></B140><B150><B151>W1</B151><B155><B1551>de</B1551><B1552>Beschreibung</B1552><B1551>en</B1551><B1552>Description</B1552><B1551>fr</B1551><B1552>Description</B1552></B155></B150><B190>EP</B190></B100><B200><B210>06114732.8</B210><B220><date>20060530</date></B220><B240><B241><date>20070613</date></B241><B242><date>20070919</date></B242></B240><B250>en</B250><B251EP>en</B251EP><B260>en</B260></B200><B400><B405><date>20100804</date><bnum>201031</bnum></B405><B430><date>20071205</date><bnum>200749</bnum></B430><B450><date>20090812</date><bnum>200933</bnum></B450><B452EP><date>20090227</date></B452EP><B480><date>20100804</date><bnum>201031</bnum></B480></B400><B500><B510EP><classification-ipcr sequence="1"><text>G06F  12/14        20060101AFI20061220BHEP        </text></classification-ipcr></B510EP><B540><B541>de</B541><B542>Integrierte Schaltungsanordnung, Verfahren zur Überwachung von Zugriffsanfragen an eine Komponente einer integrierten Schaltungsanordnung und Computerprogrammprodukt</B542><B541>en</B541><B542>Integrated circuit arrangement, a method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement and a computer program product</B542><B541>fr</B541><B542>Aménagement de circuit intégré, procédé de surveillance des demandes d'accès pour un composant d'aménagement de circuit intégré et produit de programme informatique</B542></B540><B560><B561><text>DE-A1- 19 502 626</text></B561><B561><text>US-A- 5 754 762</text></B561><B561><text>US-A- 6 047 388</text></B561></B560></B500><B700><B720><B721><snm>Jennings, David</snm><adr><str>Rottenbucher Str. 42</str><city>81377, München</city><ctry>DE</ctry></adr></B721><B721><snm>Knight, Richard</snm><adr><str>Shetlands, Far End Sheepscombe Nr</str><city>Stroud, Gloucestershire GL6 7RL</city><ctry>GB</ctry></adr></B721></B720><B730><B731><snm>Infineon Technologies AG</snm><iid>100781874</iid><irf>P31646</irf><adr><str>Am Campeon 1-12</str><city>85579 Neubiberg</city><ctry>DE</ctry></adr></B731></B730><B740><B741><snm>Viering, Jentschura &amp; Partner</snm><iid>100060432</iid><adr><str>Postfach 22 14 43</str><city>80504 München</city><ctry>DE</ctry></adr></B741></B740></B700><B800><B840><ctry>DE</ctry><ctry>FR</ctry><ctry>GB</ctry></B840><B880><date>20071205</date><bnum>200749</bnum></B880></B800></SDOBI><!-- EPO <DP n="1"> -->
<description id="desc" lang="en">
<p id="p0001" num="0001">The invention relates to an integrated circuit arrangement, a method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement and a computer program product.</p>
<p id="p0002" num="0002">A secure execution environment within a integrated circuit arrangement comprising a central microprocessor and a plurality of further circuit arrangement components such as memories or the like requires that defined regions of a shared memory can be protected against access (read and/or write) from non-trusted processes, processors or data moving engines within the system, i.e. within the integrated circuit arrangement.</p>
<p id="p0003" num="0003">A common secure execution environment is the so called TrustZone environment from ARM Ltd. This solution increases silicon area and cannot be re-used for debug purposes.</p>
<p id="p0004" num="0004">Because of the complexity of SoC (System on Chip) systems, it is common to have some type of debug watchpoint/breakpoint on the internal buses of an integrated circuit arrangement, which may be implemented as a chip. This allows on-chip data movements to be monitored for debug purposes. Such watchpoint/breakpoint units are often implemented as a set of programmable address registers which are combined with programmable registers indicating the master or process which initiated the bus transaction (e.g. HMASTER or HPROT signals of the AHB protocol (Advanced High-Performance Bus protocol). Bus accesses are compared with the programmed values. If the master and addresses match the register values (or in some<!-- EPO <DP n="2"> --> cases match addresses in the range between two programmed register values), then a debug break condition occurs. Typically such a debug trap would halt the processor to allow interactive debug to commence.</p>
<p id="p0005" num="0005">In the document <patcit id="pcit0001" dnum="US5754762A"><text>US-A-5 754 762</text></patcit> an architecture is described where a plurality of computer system components are coupled via a computer bus and wherein memory boundaries may be defined for application programs. When an application program tries to access the memory via the computer bus, it is determined whether the memory area to be accessed has an address that lies within the defined boundaries. If it does not lie within the boundaries, an interrupt is triggered to stop the memory access.</p>
<p id="p0006" num="0006">The document <patcit id="pcit0002" dnum="US6047388A"><text>US-A-6 047 388</text></patcit> describes a computer system in which it may be checked for a memory request whether the request address is within a stored address range. If the address is not within the address range, the address is considered as being invalid and an interrupt is issued.</p>
<p id="p0007" num="0007">In <patcit id="pcit0003" dnum="DE19502626A1"><text>DE 195 02 626 A1</text></patcit> a data processing system is described having an address register for storing an upper boundary and an address register for storing a lower boundary and a comparator which checks in case of a memory access whether the access address lies with the address range defined by the boundaries. In case of an access to an address that is not within the address range, an interrupt signal may be generated for a central unit.</p>
<p id="p0008" num="0008">According to an embodiment of the invention, an integrated circuit arrangement is provided, comprising a plurality of circuit arrangement components, at least one coupler coupling the circuit arrangement components comprising, for each circuit arrangement component a computer bus that is associated with the circuit arrangement component and via which the circuit arrangement component may be accessed<!-- EPO <DP n="3"> --> wherein for each computer bus an address range may be set independently of the address ranges set for the other computer busses and a coupler watcher checking as to whether an access request to a circuit arrangement components has a request address, that identifies at least a part of the circuit arrangement component, to which access is requested, that lies within the address range set for the computer bus associated with the circuit arrangement component to which the access is requested, and, dependent on whether the request address lies within the predetermined address range, the coupler watcher accepts the access request or generates a false access signal.</p>
<p id="p0009" num="0009">According to another embodiment of the invention, a method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement, comprising a plurality of circuit arrangement components and at least one coupler coupling the circuit arrangement components, comprising, for each circuit arrangement component a computer bus that is associated with the circuit arrangement component and via which the circuit arrangement component may be accessed wherein for each computer bus an address range may be set independently of the address ranges set for the other computer busses, is provided. The method comprises receiving an access request to a circuit arrangement components, determining a request address that identifies at least a part of the circuit arrangement component, to which access is requested, checking, by a common coupler watcher of the integrated circuit arrangement, as to whether the request address lies within the address range set for the computer bus associated with the circuit arrangement component to which the access is requested, and dependent on whether the request address lies within the predetermined address range, accepting the access request or generating a false access signal.<!-- EPO <DP n="4"> --></p>
<p id="p0010" num="0010">According to still another embodiment of the invention, a computer program product is provided for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement, comprising a plurality of integrated circuit arrangement components and at least one coupler coupling the circuit arrangement components, comprising, for each circuit arrangement component a computer bus that is associated with the circuit arrangement component and via which the circuit arrangement component may be accessed wherein for each computer bus an address range may be set independently of the address ranges set for the other computer busses, the computer program product, when being executed by a processor, comprising the above described method.</p>
<p id="p0011" num="0011">According to an embodiment of the invention, one advantage may be seen in that a common interrupt mechanism, which usually is used for providing access to an integrated circuit arrangement component, is now provided for access control and, e.g. in response to an unauthorized access request to an integrated circuit arrangement component, generates a false access signal and, e.g. resets the integrated circuit arrangement in order to protect it, thereby providing a secure execution environment.</p>
<p id="p0012" num="0012">This is achieved with little or no impact on silicon area and therefore hardware cost.</p>
<p id="p0013" num="0013">In accordance with one embodiment of the invention, hardware may be used which is already likely to exist within the system (i.e. the integrated circuit arrangement), but can be used for other purposes, namely for access control purposes.</p>
<p id="p0014" num="0014">According to one embodiment of the invention, the same functionality can be reused to provide a simple but effective secure execution environment. In a secure operation mode the<!-- EPO <DP n="5"> --> address registers would only be able to be initialized by the trusted process. It can program address regions into the registers which cannot subsequently be changed by non-trusted processes. When the bus debug system is used in this mode, any address/master match condition may cause a soft reset of the system (instead of the usual debug trap), an interrupt, or removal of access to some hardware resources. Consequently this technique could be used to prevent any accesses of the sensitive memory region by non-trusted masters. Using this protection scheme alongside key management and encryption<!-- EPO <DP n="6"> --> techniques, it is possible to implement a secure execution environment in any multiprocessor/multimaster system.</p>
<p id="p0015" num="0015">The described embodiments of the invention can be implemented in hardware, i.e. by means of one or a plurality of special integrated circuit(s), in software, i.e. by means of one or a plurality of computer programs, or in an arbitrary hybrid form, i.e. in any partitioning partly in hardware and partly in software.</p>
<p id="p0016" num="0016">The described embodiments of the invention relate to the integrated circuit arrangement, the method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement as well as to the computer program product, as appropriate.</p>
<p id="p0017" num="0017">According to one exemplary embodiment of the invention, the plurality of circuit arrangement components comprising at least one circuit arrangement component of a group selected from:
<ul id="ul0001" list-style="bullet" compact="compact">
<li>volatile memory,</li>
<li>non-volatile memory,</li>
<li>memory controller,</li>
<li>microprocessor,</li>
<li>digital signal processor,</li>
<li>system control logic,</li>
<li>mobile radio communication module,</li>
<li>crypto engine,</li>
<li>serial interface,</li>
<li>parallel interface,</li>
<li>periphery component driver.</li>
</ul></p>
<p id="p0018" num="0018">Furthermore, in accordance with another embodiment of the invention, where at least one coupler comprises at least one data bus.<!-- EPO <DP n="7"> --></p>
<p id="p0019" num="0019">In accordance with yet another embodiment of the invention, the at least one coupler has at least one address bus.</p>
<p id="p0020" num="0020">In general, the at least one coupler may have any number of control buses, data buses or address buses. In one embodiment, the at least one coupler may comprise one or more on-chip buses for one or a plurality of on-chip memory, e.g. volatile memory or non-volatile memory. Furthermore, the at least one coupler may comprise one or more on-chip buses for one ore a plurality of chip-external memory, e.g. volatile memory or non-volatile memory. Moreover, the at least one coupler may comprise one or more on-chip peripheral control buses for controlling one ore a plurality of peripheral units, e.g. a hard disk, a keyboard, a computer mouse, a trackball, any other input/output devices, one or more display devices, other communication modules, e.g. radio communication modules or the like.</p>
<p id="p0021" num="0021">According to another embodiment of the invention, the coupler watcher, e.g. the bus watcher, comprises one or a plurality of address registers storing at least one address that forms the address range, e.g. the address range of a memory as a circuit arrangement component, wherein the portion of the memory identified by the address range is sensitive and should be protected.</p>
<p id="p0022" num="0022">Furthermore, the address range may be a range selected from a group consisting of the following address ranges:
<ul id="ul0002" list-style="bullet" compact="compact">
<li>an address range including all addresses that are higher than a predetermined address,</li>
<li>an address range including all addresses that are equal to or higher than a predetermined address,</li>
<li>an address range including all addresses that are lower than a predetermined address,</li>
<li>an address range including all addresses that are equal to or lower than a predetermined address,<!-- EPO <DP n="8"> --></li>
<li>an address range including all addresses that lie between a first predetermined address and a second predetermined address,</li>
<li>an address range including all addresses that lie between a first predetermined address and a second predetermined address, including the first predetermined address and the second predetermined address,</li>
<li>an address range including all addresses that lie outside an address interval that is determined by a first predetermined address and a second predetermined address,</li>
<li>an address range including all addresses that lie outside an address interval that is determined by a first predetermined address and a second predetermined address, including the first predetermined address and the second predetermined address.</li>
</ul></p>
<p id="p0023" num="0023">According to another embodiment of the invention, the coupler watcher further checks as to whether an access request to one or a plurality of the circuit arrangement components has a request address that lies within another predetermined address range, and, dependent on whether the request address lies within the other predetermined address range, the coupler watcher generates an access interrupt signal for granting access to the circuit arrangement component.</p>
<p id="p0024" num="0024">In other words, the coupler watcher may function as a security access control device as well as a common bus watcher for providing access to the respective components of the integrated circuit arrangement.</p>
<p id="p0025" num="0025">The false access signal may be an access interrupt signal.</p>
<p id="p0026" num="0026">In accordance with another embodiment of the invention, a security controller may be provided denying the access to the circuit arrangement component in response to the response of the false access signal. This has the advantage that a secure and easy access control mechanism is provided.<!-- EPO <DP n="9"> --></p>
<p id="p0027" num="0027">Furthermore, the security controller may be configured to reset (e.g. re-boot) the integrated circuit arrangement to a predetermined status (e.g. a new boot status).</p>
<p id="p0028" num="0028">These and other features of the invention will be better understood when taken in view of the following drawings and a detailed description.
<dl id="dl0001">
<dt>Figure 1</dt><dd>illustrates a mobile radio communication device in accordance with an embodiment of the present invention;</dd>
<dt>Figure 2</dt><dd>illustrates a processor system of the mobile radio communication device in accordance with an embodiment of the present invention;</dd>
<dt>Figure 3</dt><dd>illustrates a bus watcher of the mobile radio communication device in accordance with an embodiment of the present invention;</dd>
<dt>Figure 4</dt><dd>illustrates a flow diagram showing the method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement of the mobile radio communication device in accordance with an embodiment of the present invention;</dd>
<dt>Figure 5</dt><dd>illustrates a block diagram showing the structure of a bus watcher of the mobile radio communication device in accordance with an embodiment of the present invention; and</dd>
<dt>Figure 6</dt><dd>illustrates a block diagram showing the breakpoint generation for one bus of the mobile radio communication device in accordance with an embodiment of the present invention.</dd>
</dl><!-- EPO <DP n="10"> --></p>
<p id="p0029" num="0029"><figref idref="f0001"><b>Figure 1</b></figref> shows a mobile radio communication device 100 in accordance with an exemplary embodiment of the invention. The mobile radio communication device 100 is configured to provide the communication protocol stacks and functions in accordance with a desired mobile radio communication standard, e.g. a mobile radio communication standard of the second generation such as GSM (Global System Mobile), or a mobile radio communication standard of the third generation, e.g. a mobile radio communication standard according to a 3GPP (3<sup>rd</sup> Generation Partnership Project) standard or according to a 3GPP2 standard.</p>
<p id="p0030" num="0030">The mobile radio communication device 100 may be configured to provide the communication protocol stacks and functions in accordance with one of the following mobile radio communication standards:
<ul id="ul0003" list-style="bullet" compact="compact">
<li>Universal Mobile Telecommunications System (UMTS),</li>
<li>General Packet Radio Services (GPRS),</li>
<li>Enhanced Data-Rates for GSM Evolution (EDGE),</li>
<li>Code Division Multiple Access 2000 (CDMA2000),</li>
<li>Freedom of Mobile Multimedia Access (FOMA).</li>
</ul></p>
<p id="p0031" num="0031">The mobile radio communication device 100 has a housing 101 and an antenna 102 coupled to the housing 101. Furthermore, the mobile radio communication device 100 has the common components of a mobile radio communication device such as a loudspeaker 103, a microphone 104, a display 105 and an array of keys 106. The key array 106 comprises function keys 107, 108, 109, 110 such as a communication connection setup key 107, a communication connection termination key 108, a general function key 109 or a menu control key 110. Furthermore, numerical keys 111 are provided in the key array 106 as well as a "*"-key 112 and a "#"-key 113.</p>
<p id="p0032" num="0032">Furthermore, the mobile radio communication device 100 has a processor system 250 as shown in <figref idref="f0002"><b>figure 2</b></figref><b>.</b><!-- EPO <DP n="11"> --></p>
<p id="p0033" num="0033">Thus, <figref idref="f0002">figure 2</figref> illustrates a processor system 250 of the mobile radio communication device 100 in accordance with an embodiment of the present invention. The processor system 250 comprises a processor chip 200 and a digital signal processor 213 and one or a plurality of mobile radio communication modules 214.</p>
<p id="p0034" num="0034">The processor chip 200 comprises a microprocessor 201, in accordance with one embodiment of the invention, an ARM 926 EJ-S microprocessor 201, a boot read only memory (ROM) 202 that includes at least a part of the boot routine for booting the processor chip 200. Furthermore, a volatile on-chip local memory unit 203 is provided, for example a dynamic random access memory (DRAM).</p>
<p id="p0035" num="0035">The processor chip 200 further includes one or a plurality of interfaces, e.g. a debug interface 204 which enables a connection to a debugging tool, a serial interface 205 such as a Universal Serial Bus (USB) interface or a Universal Asynchronous Receiver Transmitter (UART) interface, which, e.g. provides a connection to a personal computer or a workstation, generally speaking, to a chip-external computer. The serial interface 205 can be used for loading computer programs onto the mobile radio communication device 100. A further interface that is provided is an external bus unit interface 209 for communication with chip-external memories such as a chip-external non-volatile memory 211 such as a flash memory or a chip-external volatile memory 212 such as a chip-external dynamic random access memory (DRAM).</p>
<p id="p0036" num="0036">The processor chip 200 further includes a crypto engine 206 that provides one or a plurality cryptographic functions such as
<ul id="ul0004" list-style="bullet" compact="compact">
<li>a symmetric encryption/decryption function, e.g. DES (Data Encryption Standard), 3DES (Triple Data Encryption Standard) or AES (Advanced Encryption Standard),<!-- EPO <DP n="12"> --></li>
<li>an asymmetric encryption/decryption function, e.g. RSA,</li>
<li>a one-way hash-function, e.g. MD5 or SHA-1 (Secure Hash Algorithm 1),</li>
<li>a random number generation function.</li>
</ul></p>
<p id="p0037" num="0037">The crypto engine 206 may comprise respective hardware accelerators for the implemented cryptographic function(s). The access to the crypto engine 206 is controlled by means of a crypto engine access control means 215.</p>
<p id="p0038" num="0038">The processor chip 200 further includes a system control unit 207. The system control unit 207 is a central unit containing logic to control the functionality of several components of the processor chip 200.</p>
<p id="p0039" num="0039">Further, electric fuses (e-fuses) 208 are provided for use in the crypto engine 206 and the system control unit 207. The e-fuses 208 are used to store unique/customizing information on the processor chip 200. Each e-fuse 208 is a single bit of information which can be set to a value after the processor chip 200 has been fabricated. A special tool is usually used to set the value (or blow the respective e-fuse 208). Once an e-fuse 208 has been blown, it cannot be changed anymore.</p>
<p id="p0040" num="0040">The processor chip 200 makes use of the e-fuses 208 so that the processor chip 200 behavior can be customized in a non-volatile and secure manner for the mobile radio communication device 100. The system control unit 207 contains a unique fuse ID for each processor chip 200, which is usually blown by the processor chip 200 manufacturer.</p>
<p id="p0041" num="0041">The microprocessor 201, the boot ROM 202, the on-chip local memory 203, the debug interface 204, the serial interface 205, the crypto engine 206, the system control unit 207 and the external bus interface 209 are connected with each other by means of an on-chip bus unit 210, the structure of which will be described in more detail below.<!-- EPO <DP n="13"> --></p>
<p id="p0042" num="0042">According to this embodiment of the invention, the digital signal processor 213 is a TEAKLite digital signal processor, although any other suitable digital signal processor may be used in alternative embodiments of the invention.</p>
<p id="p0043" num="0043">According to this embodiment of the invention, the at least one mobile radio communication module 214 is configured to provide the basic functions of a mobile radio protocol stack, for example according to GSM, alternatively or in addition according to a mobile radio protocol stack of the third generation such as one of the mobile radio communication standards that have been described above.</p>
<p id="p0044" num="0044"><figref idref="f0003"><b>Figure 3</b></figref> shows the on-chip bus unit 210 in more detail. As shown in <figref idref="f0003">Figure 3</figref>, the on-chip bus unit 210 comprises a bus watcher 301, which is configured to listen to the signals that are transmitted via the respective bus the on-chip bus unit 210 is connected to. The operation of the bus watcher 301 will be described in more detail below.</p>
<p id="p0045" num="0045">Furthermore, the on-chip bus unit 210 comprises a plurality of buses, for example one or more memory buses for transmitting signals from and to one or more memories, or one or more control buses for transmitting control signals to one or more peripheral units.</p>
<p id="p0046" num="0046">According to this embodiment of the invention, the on-chip bus unit 210 comprises two memory buses, one first memory bus 302, in the following also referred to as AHB (ARM Data), for transmitting signals from and to one or more chip-internal (on-chip) memories, in this case the local memory 203, and one second memory bus 303, in the following also referred to as AHB_FLASH, for transmitting signals from and to one or more chip-external memories, in this case the non-volatile memory 211 and/or the volatile chip-external DRAM 212.<!-- EPO <DP n="14"> --></p>
<p id="p0047" num="0047">According to this embodiment of the invention, the on-chip bus unit 210 further comprises four buses 304, 305, 306, 307, namely
<ul id="ul0005" list-style="bullet" compact="compact">
<li>a first bus 304, in the following also referred to as AHB (ARM Inst), for fetching instructions from memory for the microprocessor 201,</li>
<li>a second bus 304, in the following also referred to as AHB (ARM Data), for the microprocessor to read and write data,</li>
<li>a third bus 305, in the following also referred to as AHB (DMA1 Data), for the DMA controller to read and write data</li>
<li>a fourth bus 306, in the following also referred to as AHB (DMA2 Data), for the DMA controller to read and write data,</li>
<li>a fifth bus 307, in the following also referred to as AHB (Grafic Data), for graphic display components to read and write data (not shown), e.g. the display 105.</li>
</ul></p>
<p id="p0048" num="0048">In an embodiment of the invention, the buses 302, 303, 304, 305, 306, 307 are AHB buses (Advanced High-Performance Bus).</p>
<p id="p0049" num="0049">The microprocessor 201 is coupled to each of the buses 302, 304, 305, 306, 307. Furthermore, the bus watcher 301 is also coupled to each of the buses 302, 303, 304, 305, 306, 307 except for the second memory bus 303, for which no bus watcher monitoring is provided.</p>
<p id="p0050" num="0050"><figref idref="f0004"><b>Figure 4</b></figref> illustrates a flow diagram 400 showing the method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement of the mobile radio communication device in accordance with an embodiment of the present invention. According to an embodiment of the invention, the method is carried out by the bus watcher 301.<!-- EPO <DP n="15"> --></p>
<p id="p0051" num="0051">After the initialization of the bus watcher 301, the access control method according to an embodiment of the invention is started (step 401). After start, the bus watcher 301 listens to the buses that it is connected to in order to receive access request signals (in other words access request messages according to the respectively used bus communication protocol), with which access to one of the connected components of the processor system 250 is requested.</p>
<p id="p0052" num="0052">If the coupler watcher, e.g. the bus watcher 301 receives an access request message via any of the connected buses 302, 303, 304, 305, 306, 307, it parses the request address from the received access request message (step 403). The request address identifies at least a part of the circuit arrangement component, to which access is requested, e.g. the request address identifies the component or, e.g. in case that the component is a memory, the request address identifies a region (e.g. a sector, block, etc.) of the addressed memory. After having determined the request address, the coupler watcher, e.g. the bus watcher 301, determines whether the determined request address lies within a predetermined address range (step 404), wherein the address range can be set by the user for each bus and/or each component independently.</p>
<p id="p0053" num="0053">The address range may be a range selected from a group consisting of the following address ranges:
<ul id="ul0006" list-style="bullet" compact="compact">
<li>an address range including all addresses that are higher than a predetermined address (in other words, in this case, a first threshold value is pre-set and it is determined whether the determined request address has a value that is higher than the first threshold value),</li>
<li>an address range including all addresses that are equal to or higher than a predetermined address (in other words, in this case, a first threshold value is pre-set and it is determined whether the determined request<!-- EPO <DP n="16"> --> address has a value that is equal to or higher than the first threshold value),</li>
<li>an address range including all addresses that are lower than a predetermined address (in other words, in this case, a second threshold value is pre-set and it is determined whether the determined request address has a value that is lower than the second threshold value),</li>
<li>an address range including all addresses that are equal to or lower than a predetermined address (in other words, in this case, a second threshold value is pre-set and it is determined whether the determined request address has a value that is equal to or lower than the second threshold value),</li>
<li>an address range including all addresses that lie between a first predetermined address and a second predetermined address (in other words, in this case, a first threshold value and a second threshold value are pre-set and it is determined whether the determined request address has a value that lies in the interval between the first threshold value and the second threshold value, not including the first threshold value and the second threshold value),</li>
<li>an address range including all addresses that lie between a first predetermined address and a second predetermined address, including the first predetermined address and the second predetermined address (in other words, in this case, a first threshold value and a second threshold value are pre-set and it is determined whether the determined request address has a value that lies in the interval between the first threshold value and the second threshold value, including the first threshold value and the second threshold value),</li>
<li>an address range including all addresses that lie outside an address interval that is determined by a first predetermined address and a second predetermined address (in other words, in this case, a first threshold value and a second threshold value are pre-set and it is<!-- EPO <DP n="17"> --> determined whether the determined request address has a value that lies outside the interval between the first threshold value and the second threshold value, not including the first threshold value and the second threshold value),</li>
<li>an address range including all addresses that lie outside an address interval that is determined by a first predetermined address and a second predetermined address, including the first predetermined address and the second predetermined address (in other words, in this case, a first threshold value and a second threshold value are pre-set and it is determined whether the determined request address has a value that lies outside the interval between the first threshold value and the second threshold value, including the first threshold value and the second threshold value).</li>
</ul></p>
<p id="p0054" num="0054">If the determined request address does not lie within the predetermined address range ("No" in step 404), the coupler watcher generates a false access signal (step 405). In accordance with one embodiment of the invention, the bus watcher 301 in this case generates a soft reset signal and transmits it to the microprocessor 201, thereby effecting a soft reset or re-boot of the processor system 250. Consequently, e.g. any accesses of a sensitive memory region or even of a sensitive circuit arrangement component by a non-trusted master component can be prevented in a very easy and effective manner.</p>
<p id="p0055" num="0055">It should be mentioned, that in addition to this mechanism, key management techniques and encryption techniques, generally speaking, cryptographic techniques may be used for access control to a sensitive memory region or even to a sensitive circuit arrangement component.</p>
<p id="p0056" num="0056">If the determined request address lies within the predetermined address range ("Yes" in step 404), the coupler<!-- EPO <DP n="18"> --> watcher grants access to the requested component or memory region (step 406), e.g. by generating a corresponding access grant signal.</p>
<p id="p0057" num="0057">In an embodiment of the invention, the bus watcher 301 contains five identical sub blocks 501, 502, 503, 504, 505 for the five buses 302, 304, 305, 306, 307, the bus watcher 301 is coupled to (see <figref idref="f0005"><b>figure 5</b></figref><b>).</b> Each of the break-point generation sub blocks 501, 502, 503, 504, 505 is assigned to one respectively monitored bus 302, 304, 305, 306, 307.</p>
<p id="p0058" num="0058">The names used in the blocks of <figref idref="f0005">figure 5</figref> and in the following description are parameterized where necessary with "x":
<ul id="ul0007" list-style="bullet" compact="compact">
<li>for the first memory bus 302 AHB (ARM Data); x = AD;</li>
<li>for the second control bus 304 AHB (ARM Inst); x = AI;</li>
<li>for the third control bus 305 AHB (DMA1 Data); x = DM1;</li>
<li>for the fourth control bus 306 AHB (DMA2 Data); x = DM2;</li>
<li>for the fifth control bus 307 AHB (Grafic Data); x = GD.</li>
</ul></p>
<p id="p0059" num="0059">The bus watcher 301 is on one port of the AHB bus matrix comprising the buses 302, 303, 304, 305, 306, 307 and monitors traffic on the following five AHB buses:
<ul id="ul0008" list-style="bullet" compact="compact">
<li>the first memory bus 302;</li>
<li>the second control bus 304;</li>
<li>the third control bus 305;</li>
<li>the fourth control bus 306;</li>
<li>the fifth control bus 307.</li>
</ul></p>
<p id="p0060" num="0060">The bus watcher 301 further contains one central block 506 for the AHB configuration interface and global control.</p>
<p id="p0061" num="0061">The central block 506 collects the breakpoint requests from the sub blocks 501, 502, 503, 504, 505, can mask them and transfers the break request to either a multicore debug block (not shown) or the system control unit 207. The central block 506 captures the status of the sub block requests to allow the debugger or software to determine the source of the<!-- EPO <DP n="19"> --> break. If the bus watcher 301 is being used to enforce access restrictions for a security policy as is the case according to an embodiment of the invention, then the break request output may be routed to the system control unit 207. In the event of an attempted access which violates the security restrictions set up in the bus watcher 301, the system control unit 207 can automatically issue a processor chip 200 reset.</p>
<p id="p0062" num="0062">The central block 506 contains an ABW_ID register 507 and an ABM_CONTROL register 508.</p>
<p id="p0063" num="0063">As described above, there are provided five identical sub blocks 501, 502, 503, 504, 505, one sub block for each bus 302, 304, 305, 306, 307 to be monitored.</p>
<p id="p0064" num="0064">Each sub block 501, 502, 503, 504, 505 generates a trap signal brk_out_x dependent on the content of the control registers, which will be described in more detail below, which are provided in the bus watcher 301.</p>
<p id="p0065" num="0065">The implementation of the breakpoint logic for one sub bus block 501, 502, 503, 504, 505 is shown in <figref idref="f0006"><b>figure 6</b></figref><b>.</b></p>
<p id="p0066" num="0066">The trap values are defined in the following registers (listed in alphabetic order):
<ul id="ul0009" list-style="bullet" compact="compact">
<li>ABW_xADR1 register 601;</li>
<li>ABW_xADR2 register 602;</li>
<li>ABW_xBOS register 603;</li>
<li>ABW_xGRNT register 604.</li>
</ul></p>
<p id="p0067" num="0067">The way the conditions are combined is defined by the content of an ABW_xCNTL register 605.</p>
<p id="p0068" num="0068">The ABW_xGRNT register 604 contains the mask which is combined with the grant lines HGRANTx from the bus arbiter, which is stored in an additionally provided ABW_xGNTT<!-- EPO <DP n="20"> --> register 606. This allows any number of masters to be included in the trigger. The content of the ABW_xGRNT register 604 is compared with the content ABW_xGNTT register 606 received from the grant lines HGRANTx (block 607) and, if appropriate, a bus master break event signal 608 is generated and provided to a final mask and select block 609, which is controlled by means of the content of the ABW_xCNTL register 605.</p>
<p id="p0069" num="0069">According to this embodiment of the invention, there is only one master (in general, any number of masters can be provided and handled) and the ABW_xGRNT register 604 and the additionally provided ABW_xGNTT register 606 have no function.</p>
<p id="p0070" num="0070">The two address registers, namely the ABW_xADR1 register 601 and the ABW_xADR2 register 602, are used to define the address range for the trigger.</p>
<p id="p0071" num="0071">Two comparators, e.g. a first comparator 610 for the ABW_xADR1 register 601 and a second comparator 611 for the ABW_xADR2 register 602, are provided.</p>
<p id="p0072" num="0072">The first comparator 610 provides an "Is-equal" output 612 and an "Is-larger" output 613, wherein a High signal is provided at the "Is-equal" output 612 in case that the content of the ABW_xADR1 register 601 is equal to the content of an additionally provided ABW_xGADRT register 614 received from the grant lines HGRANTx. In case that the content of the ABW_xADR1 register 601 is not equal to the content of the ABW_xGADRT register 614, a Low signal is provided at the "Is-equal" output 612. Furthermore, a High signal is provided at the "Is-larger" output 613 in case that the content of the ABW_xADR1 register 601 is larger than the content of the additionally provided ABN_xGADRT register 614 received from the grant lines HGRANTx. In case that the content of the ABW_xADR1 register 601 is not larger than the content of the<!-- EPO <DP n="21"> --> ABW_xGADRT register 614, a Low signal is provided at the "Is-larger" output 613.</p>
<p id="p0073" num="0073">The second comparator 611 provides an "Is-equal" output 615 and an "Is-smaller" output 616, wherein a High signal is provided at the "Is-equal" output 615 in case that the content of the ABW_xADR2 register 602 is equal to the content of the ABW_xGADRT register 614 received from the grant lines HGRANTx. In case that the content of the ABW_xADR2 register 602 is not equal to the content of the ABW_xGADRT register 614, a Low signal is provided at the "Is-equal" output 615. Furthermore, a High signal is provided at the "Is-smaller" output 616 in case that the content of the ABW_xADR2 register 602 is smaller than the content of the ABW_xGADRT register 614 received from the grant lines HGRANTx. In case that the content of the ABW_xADR2 register 602 is not smaller than the content of the ABW_xGADRT register 614, a Low signal is provided at the "Is-smaller" output 616.</p>
<p id="p0074" num="0074">The outputs 612, 613, 615, 616 of the comparators 610, 611 are connected to a range detection circuit 617. The range detection circuit 617 logically combines the signals provided by the comparators 610, 611 to generate the following signals:
<ul id="ul0010" list-style="bullet" compact="compact">
<li>an outside/inside signal 618, wherein the outside/inside signal 618 has a High signal level if the content of the ABW_xGADRT register 614 lies outside the interval between the values defined by the content of the ABW_xADR1 register 601 and the content of the ABW_xADR2 register 602, and wherein the outside/inside signal 618 has a Low signal level if the content of the ABW_xGADRT register 614 lies inside the interval between the values defined by the content of the ABW_xADR1 register 601 and the content of the ABW_XADR2 register 602;</li>
<li>an above signal 619, wherein the above signal 619 has a High signal level if the content of the ABW_xGADRT<!-- EPO <DP n="22"> --> register 614 is larger than the value defined by the content of the ABW_xADR1 register 601 and has a Low signal level if the content of the ABW_xGADRT register 614 is not larger than the value defined by the content of the ABW_xADR1 register 601;</li>
<li>a below signal 620, wherein the below signal 620 has a High signal level if the content of the ABW_xGADRT register 614 is smaller than the value defined by the content of the ABW_xADR2 register 602 and has a Low signal level if the content of the ABW_xGADRT register 614 is not smaller than the value defined by the content of the ABW_xADR2 register 602;</li>
<li>an OR signal 621, wherein the OR signal 621 has a High signal level if the content of the ABW_xGADRT register 614 is equal to value defined by the content of the ABW_xADR1 register 601 or if the content of the ABW_xGADRT register 614 is equal to the value defined by the content of the ABW_xADR2 register 602, and has a Low signal level if the content of the ABW_xGADRT register 614 is not equal to value defined by the content of the ABW_xADR1 register 601 and if the content of the ABW_xGADRT register 614 is not equal to the value defined by the content of the ABW_xADR2 register 602.</li>
</ul></p>
<p id="p0075" num="0075">The generated signals 618, 619, 620, 621 are inputs to the final mask and select block 609, which is controlled by means of the content of the ABW_xCNTL register 605.</p>
<p id="p0076" num="0076">The ABW_xBOS register 603 defines a mask and trigger values for the bus operation signals (content of the ABW_xBOST register 622 received from the grant lines HGRANTx) which are driven in the address phase of a bus access (mask and compare operation in block 623). These triggers can be provided as an input to the final mask and select block 609 (e.g. as a bus control break event 624) and can then be combined with address ranges in different ways as defined by the content of the ABW_xCNTL register 605.<!-- EPO <DP n="23"> --></p>
<p id="p0077" num="0077">The final mask and select block 609 provides an output signal 625 brk_out_x_n which will be on Low signal level for as long as the respective condition is met. This will be a minimum of one AHB block cycle. When the condition is met, the capture registers ABW_xGNTT register 606, ABW_xGADRT register 614 and ABW_xBOST register 622 will be written with the relevant signal values.</p>
<p id="p0078" num="0078">Writing to the ARM bit in the DBxCNTL register will rearm the circuitry and set the five capture registers mentioned above to their default values; this also sets the TRIG bit in the DBxCNTL register to the value "1".</p>
<p id="p0079" num="0079">In order to comply with the security concept in accordance with an embodiment of the invention, it is provided to have an option to restrict access to the registers which control the bus watcher 301 breakpoints.</p>
<p id="p0080" num="0080">In an embodiment of the invention, during a boot sequence, the software can select whether the bus watcher 301 is an open resource or a secure resource. If the bus watcher 301 is to be used as a mechanism for enforcing the security concept, then a newly provided register bit EINIT should be written with a value "1". If the register bit EINIT is not written, the bus watcher 301 remains open and available for unrestricted use or debug by any software. Once the register bit EINIT is set to the value "1", it cannot be subsequently rewritten with the value "0". When the register bit EINIT is set to the value "1", write attempts to the bus watcher registers will only succeed while a signal SEC_ACC is asserted. When the signal SEC_ACC is deasserted (i.e. outside a boot or secure phase), write attempts to the bus watcher registers will fail with a bus error response.<!-- EPO <DP n="24"> --></p>
<p id="p0081" num="0081">In one embodiment of the invention, the following registers are provided, wherein their content has the respective following meaning (listed in alphabetic order):
<ul id="ul0011" list-style="bullet" compact="compact">
<li>ABW_xADR1 register:<br/>
Bus watcher address 1 for sub-block x;</li>
<li>ABW_xADR2 register:<br/>
Bus watcher address 2 for sub-block x;</li>
<li>ABW_xADRT register:<br/>
Bus watcher trapped address for sub-block x;</li>
<li>ABW_xBOS register:<br/>
Bus watcher bus operation signals for sub-block x;</li>
<li>ABW_xBOST register:<br/>
Bus watcher trapped bus operation signals for sub-block x;</li>
<li>ABW_xCNTL register:<br/>
Bus watcher control for sub-block x;</li>
<li>ABW_CONTROL register:<br/>
Control of bus watcher block;</li>
<li>ABW_xGNTT register:<br/>
Bus watcher trapped grant lines for sub-block x;</li>
<li>ABW_xGRNT register:<br/>
Bus watcher grant mask for sub-block x;</li>
<li>ABW_ID register:<br/>
Bus watcher identification register.</li>
</ul></p>
<p id="p0082" num="0082">The block bus watcher has no extra clock control registers. It runs with the AHB clock.</p>
<p id="p0083" num="0083">The field description of the ABW_CONTROL register 508 as a status and control register in accordance with an embodiment of the present invention is as shown in table 1 (listed in alphabetic order):<!-- EPO <DP n="25"> -->
<tables id="tabl0001" num="0001">
<table frame="all">
<title>Table 1: ABW_CONTROL register 508</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="23mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="103mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry/>
<entry>1</entry>
<entry>R</entry>
<entry>Reserved - Read as '0'</entry></row>
<row rowsep="0">
<entry>ADM</entry>
<entry>1</entry>
<entry>Rw</entry>
<entry><b>Mask for brk_out_AD-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>1: Break from sub block ABW_DBAD to be used for abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>0: Break from sub block ABW_DBAD not used for abw_brk_n_o</entry></row>
<row rowsep="0">
<entry>ADS</entry>
<entry>1</entry>
<entry>R</entry>
<entry><b>Status of brk_out_AD-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>0: Break from sub block ABW_DBAD caused abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>1 No break from sub block ABW_DBAD used for abw_brk_n_o</entry></row>
<row rowsep="0">
<entry>AIM</entry>
<entry>1</entry>
<entry>Rw</entry>
<entry><b>Mask for brk</b>_<b>out</b>_<b>Al-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>1 Break from sub block ABW_DBA1 to be used for abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>0 Break from sub block ABW_DBA1 not used for abw_brk_n_o</entry></row>
<row rowsep="0">
<entry>AIS</entry>
<entry>1</entry>
<entry>R</entry>
<entry><b>Status of brk_out_Al-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>0 Break from sub block ABW_DBA1 caused abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>1 No break from sub block ABW_DBA1 used for abw_brk_n_o</entry></row>
<row rowsep="0">
<entry>DMM1</entry>
<entry>1</entry>
<entry>Rw</entry>
<entry><b>Mask for brk_out_DM1-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>1: Break from sub-block ABW_DBDM1 to be used for abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>0: Break from sub-block ABN_DBDM1 not used for abw_brk_n_o</entry></row>
<row rowsep="0">
<entry>DMM2</entry>
<entry>1</entry>
<entry>Rw</entry>
<entry><b>Mask for brk out DM2-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>1: Break from sub-block ABW_DBDM2 to be used for abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>0: Break from sub-block ABW_DBDM2 not used for abw_brk_n_o</entry></row>
<row rowsep="0">
<entry>DMS1</entry>
<entry>1</entry>
<entry>r</entry>
<entry><b>Status of brk_out_DM1-n</b></entry></row>
<row>
<entry rowsep="0"/>
<entry rowsep="0"/>
<entry rowsep="0"/>
<entry rowsep="0">0: Break from sub-block ABW_DBDM1</entry></row>
<row>
<entry rowsep="0"/>
<entry rowsep="0"/>
<entry rowsep="0"/>
<entry rowsep="0">caused abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>1 No break from sub-block ABW DBDM1 used for abw_brk_n_o</entry></row><!-- EPO <DP n="26"> -->
<row rowsep="0">
<entry>DMS2</entry>
<entry>1</entry>
<entry>R</entry>
<entry><b>Status of brk_out_ DM2-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>0: Break from sub-block ABW_DBDM2 caused abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>1 No break from sub-block ABW_DBDM2 used for abw_brk_n_o</entry></row>
<row rowsep="0">
<entry>GDM</entry>
<entry>1</entry>
<entry>Rw</entry>
<entry><b>Mask for brk out GD-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>1: Break from sub-block ABW_DBGD to be used for abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>0: Break from sub-block ABW_DBGD not used for abw_brk_n_o.</entry></row>
<row rowsep="0">
<entry>GDS</entry>
<entry>1</entry>
<entry>R</entry>
<entry><b>Status of brk_out_GD-n</b></entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>1: Break from sub-block ABW_DBGD caused abw_brk_n_o</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>0: No break from sub-block ABW_DBGD used for abw_brk_n_o</entry></row>
<row>
<entry>REARM</entry>
<entry>1</entry>
<entry>Rw</entry>
<entry><b>Rearms abw_brk_n_o trigger and resets status signals in bits [AIS:ADS:DMS1:DMS2:GDS]:, :</b> Write '1' to rearm, this bit always reads '0'.</entry></row>
<row>
<entry>Reserved</entry>
<entry>1</entry>
<entry/>
<entry>Reserved for additional bus</entry></row>
<row>
<entry>Reserved</entry>
<entry>3</entry>
<entry/>
<entry>Reserved for additional buses</entry></row>
<row>
<entry>Reserved</entry>
<entry>14</entry>
<entry/>
<entry>Reserved for additional buses</entry></row>
<row rowsep="0">
<entry>SEC_ACCE</entry>
<entry>1</entry>
<entry>r/w1</entry>
<entry>SEC_ACC protect all ABW registers (including this one).</entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>Reset state '0' (i.e. all ABW registers can be written regardless of SEC_ACC state)</entry></row>
<row rowsep="0">
<entry/>
<entry/>
<entry/>
<entry>Note: This bit can only be written with '1'.</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>Subsequent attempts to write with '0' will fail.</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>When this bit has been written to '1', any attempt to write to registers when SEC_ACC is deasserted will fail with a bus error. Writes when SEC_ACC is asserted will continue to transfer valid data.</entry></row><!-- EPO <DP n="27"> -->
<row>
<entry>TRIG</entry>
<entry>1</entry>
<entry>R</entry>
<entry><b>State of abw_brk_n_o trigger:</b> '1' armed / '0' fired,<br/>
Reset by writing to the REARM bit.</entry></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0084" num="0084">The following registers show the status of the bus at the time a break condition is detected:<br/>
The field description of the ABW_xBOST register 622 (e.g. the ABW_ADBOST register, the ABW_AIBOST register, the ABW_DM1BOST register, the ABW_GDBOST register and the ABW_DM2BOST register) in accordance with an embodiment of the present invention is as shown in table 2 (listed in alphabetic order) :<!-- EPO <DP n="28"> -->
<tables id="tabl0002" num="0002">
<table frame="all">
<title>Table 2: ABW_xBOST register 622</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="20mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="106mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>HBURST</b></entry>
<entry>3</entry>
<entry>r</entry>
<entry>The value of the HBURST lines when the brk_out x_n trigger occurred.</entry></row>
<row>
<entry><b>HPROT</b></entry>
<entry>4</entry>
<entry>r</entry>
<entry>The value of the HPROT lines when the brk_out_x_ n trigger occurred</entry></row>
<row>
<entry><b>HSIZE</b></entry>
<entry>3</entry>
<entry>r</entry>
<entry>The value of the HSIZE lines when the brk_out_x_n trigger occurred.</entry></row>
<row>
<entry><b>HTRANS</b></entry>
<entry>2</entry>
<entry>r</entry>
<entry>The value of the HTRANS lines when the brk_out_x_n trigger occurred.</entry></row>
<row>
<entry><b>HWRITE</b></entry>
<entry>1</entry>
<entry>r</entry>
<entry>The value of the HWRITE line when the brk_out_x_n trigger occurred. High is write. Low is read.</entry></row>
<row>
<entry><b>Reserved</b></entry>
<entry>1</entry>
<entry>r</entry>
<entry>Reserved</entry></row>
<row>
<entry><b>Reserved</b></entry>
<entry>18</entry>
<entry/>
<entry/></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0085" num="0085">The field description of the ABW_xADRT register (e.g. the ABW_ADADRT register, the ABW_AIADRT register, the ABW_DM1ADRT register, the ABW_GDADRT register and the ABW_DM2ADRT register) in accordance with an embodiment of the present invention is as shown in table 3 :
<tables id="tabl0003" num="0003">
<table frame="all">
<title>Table 3: ABW_xADRT register</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="17mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="92mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>HADDR</b></entry>
<entry>32</entry>
<entry>r</entry>
<entry>The value of the address when the brk_out_x_n trigger occurred.</entry></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0086" num="0086">The field description of the ABW_xGNTT register 606 (e.g. the ABW_ADGNTT register, the ABW_AIGNTT register, the ABW_DM1GNTT register, the ABW GDGNTT register and the ABW_DM2GNTT register) in accordance with an embodiment of the present<!-- EPO <DP n="29"> --> invention is as shown in table 4 (listed in alphabetic order) :
<tables id="tabl0004" num="0004">
<table frame="all">
<title>Table 4: ABW_xGNTT register 606</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="26mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="100mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>HMASTLOCK</b></entry>
<entry>1</entry>
<entry>RO</entry>
<entry><b>Not used for processor chip: Reserved.</b></entry></row>
<row>
<entry><b>HMASTER</b></entry>
<entry>4</entry>
<entry>RO</entry>
<entry><b>The state of the HMASTER lines when the brk_out_x_n trigger occurred.</b></entry></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0087" num="0087">In an embodiment of the invention, the bus watcher 301 masks and compares groups of bus signals with break values in registers. Each group generates internal break event signals. The internal break event signals are processed in a final mask and select stage 609 according to the content of the ABW_xCNTL register 605.</p>
<p id="p0088" num="0088">The signal groups and their control registers for the first stage are:
<ul id="ul0012" list-style="bullet" compact="compact">
<li>Address 1, ABW_xADR1;</li>
<li>Address 2, ABW_xADR2;</li>
<li>Bus Master, ABW_ADGRNT;</li>
<li>Bus control signals, ABW_xBOS.</li>
</ul></p>
<p id="p0089" num="0089">The field description of the ABW_xBOS register 603 (e.g. the ABW_ADBOS register, the ABW_AIBOS register, the ABW_DM1BOS register, the ABW_GDBOS register and the ABW_DM2BOS register) in accordance with an embodiment of the present invention is as shown in table 5 (listed in alphabetic order):<!-- EPO <DP n="30"> -->
<tables id="tabl0005" num="0005">
<table frame="all">
<title>Table 5: ABW_xBOS register 603</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="21mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="105mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>BUFFM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [BUFFM] = 1 the value of BUFFV is compared to the value on the bus.</entry></row>
<row>
<entry><b>BUFFV</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [BUFFM] = 1 this value is compared to the value on the bus<br/>
0 = not bufferable.<br/>
1 = bufferable.</entry></row>
<row>
<entry><b>CACHEM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [CACHEM] = 1 the value of CACHEV is compared to the value on the bus.</entry></row>
<row>
<entry><b>CACHEV</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [HBURSTM] = 1 this value is compared to the value on the bus<br/>
0 = not cacheable.<br/>
1 = cacheable.</entry></row>
<row>
<entry><b>DATAM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [DATAM] = 1 the value of DATAV is compared to the value on the bus.</entry></row>
<row>
<entry><b>DATAV</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [DATAM]= 1 this value is compared to the value on the bus<br/>
0 = opcode fetch.<br/>
1 = data access.</entry></row>
<row>
<entry><b>HBURSTM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [HBURSTM] = 1 the value of HBURSTV is compared to the value on the bus.</entry></row>
<row>
<entry><b>HBURSTV</b></entry>
<entry>3</entry>
<entry>rw</entry>
<entry>Burst type and length according to ARM AMBA AHB specification.<br/>
If bit [HBURSTM] = 1 this value is compared to the value on the bus.</entry></row>
<row>
<entry><b>HSIZEM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [HSIZEM] = 1 the value of HSIZEV is compared to the value on the bus.</entry></row>
<row>
<entry><b>HSIZEV</b></entry>
<entry>3</entry>
<entry>rw</entry>
<entry>Transfer size according to ARM AMBA AHB specification. If bit [HSIZEM]</entry></row><!-- EPO <DP n="31"> -->
<row>
<entry/>
<entry/>
<entry/>
<entry>= 1 this value is compared to the value on the bus.</entry></row>
<row>
<entry><b>HTRANSM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [HTRANSM] = 1 the value of HTRANSV is compared to the value on the bus.</entry></row>
<row>
<entry><b>HTRANSV</b></entry>
<entry>2</entry>
<entry>rw</entry>
<entry>Transfer type according to ARM AMBA AHB specification. If bit [HTRANSM] = 1 this value is compared to the value on the bus.</entry></row>
<row>
<entry><b>HWRITEM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [HWRITEM] = 1 the value of HWRITEV is compared to the value on the bus.</entry></row>
<row>
<entry><b>HWRITEV</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [HWRITEM] = 1 this value is compared to the value on the bus<br/>
0 = read.<br/>
1 = write.</entry></row>
<row>
<entry><b>PRIVM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [PRIVM] = 1 the value of PRIVV is compared to the value on the bus.</entry></row>
<row>
<entry><b>PRIVV</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [PRIVM] = 1 this value is compared to the value on the bus<br/>
0 = user access.<br/>
1 = privileged access.</entry></row>
<row>
<entry><b>Reserved</b></entry>
<entry>1</entry>
<entry/>
<entry>Reserved</entry></row>
<row>
<entry><b>Reserved</b></entry>
<entry>2</entry>
<entry/>
<entry>Reserved</entry></row>
<row>
<entry><b>Reserved</b></entry>
<entry>2</entry>
<entry/>
<entry/></row>
<row>
<entry><b>Reserved</b></entry>
<entry>2</entry>
<entry/>
<entry/></row>
<row>
<entry><b>Reserved</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry/></row>
<row>
<entry><b>Reserved</b></entry>
<entry>3</entry>
<entry/>
<entry/></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0090" num="0090">In the lower half of the ABW_xBOS register 603 the bus control signals which can lead to a break event are defined in value fields and bits with suffix "V". They are directly equivalent to AHB signals defined in the ARM AMBA AHB signal list.<!-- EPO <DP n="32"> --></p>
<p id="p0091" num="0091">In the upper half of the ABW_xBOS register 603 mask bits with suffix "M" are defined for each field or single bit in the lower half of the ABW_xBOS register 603. If a mask bit is high, then the bit or field it controls is compared to the equivalent bus values as part of the break event decision. If a mask bit is low, then the bit or field it controls is not used as part of the break event decision and the signals it controls are "don't care".</p>
<p id="p0092" num="0092">A bus control signal break event is only active if all enabled bus control fields are identical to their equivalent bus signals. When no field is enabled, the bus control signal break event is also active. The final break condition selection is controlled by the ABW_xCNTL register 605.</p>
<p id="p0093" num="0093">The field description of the ABW_xADR2 register 602 (e.g. the ABW_ADADR2 register, the ABW_AIADR2 register, the ABW_DM1ADR2 register, the ABW_GDADR2 register and the ABW_DM2ADR2 register) in accordance with an embodiment of the present invention is as shown in table 6:
<tables id="tabl0006" num="0006">
<table frame="all">
<title>Table 6: ABW_xADR2 register 602</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="14mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="112mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>ADR2</b></entry>
<entry>32</entry>
<entry>rw</entry>
<entry>Address 2 for the brk_out_x_n_trigger. If the AHB bus address &lt;= or = to ADR2 signals are generated for the second break condition stage controlled by the <b>ABW_xCNTL</b> register.</entry></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0094" num="0094">The field description of the ABW_xADR1 register 601 (e.g. the ABW_ADADR1 register, the ABW_AIADR1 register, the ABW_DM1ADR1 register, the ABW_GDADR1 register and the ABW_DM2ADR1<!-- EPO <DP n="33"> --> register) in accordance with an embodiment of the present invention is as shown in table 7:
<tables id="tabl0007" num="0007">
<table frame="all">
<title>Table 7: ABW_xADR1 register 601</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="14mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="112mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>ADR1</b></entry>
<entry>32</entry>
<entry>rw</entry>
<entry>Address 1 for the brk_out_x_n_trigger. If the AHB bus address &gt;= or = to ADR1 signals are generated for the second break condition stage controlled by the <b>ABW_xCNTL</b> register.</entry></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0095" num="0095">The field description of the ABW_xGRNT register 604 (e.g. the ABW_ADGRNT register, the ABW_AIGRNT register, the ABW_DMGRNT register, the ABW_GDGRNT register and the ABW_DM2GRNT register) in accordance with an embodiment of the present invention is as shown in table 8 (listed in alphabetic order) :<!-- EPO <DP n="34"> -->
<tables id="tabl0008" num="0008">
<table frame="all">
<title>Table 8: ABW_xGRNT register 604</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="21mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="105mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>HMASTLM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>Reserved: Not used in processor chip.</entry></row>
<row>
<entry><b>HMASTLV</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>Reserved: Not used in processor chip.</entry></row>
<row>
<entry><b>HMASTM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>If bit [HMASTM] = 1 the value of HMASTV is compared to the value on the bus.</entry></row>
<row>
<entry><b>HMASTV</b></entry>
<entry>4</entry>
<entry>rw</entry>
<entry>If bit [HMASTM] = 1 this value is compared to the master number from the bus arbiter.</entry></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0096" num="0096">The field description of the ABW_xCNTL register 605 (e.g. the ABW_ADCNTL register, the ABW_AICNTL register, the ABW_DMCNTL register, the ABW_GDCNTL register and the ABW_DM2CNTL register) in accordance with an embodiment of the present invention is as shown in table 9 (listed in alphabetic order):
<tables id="tabl0009" num="0009">
<table frame="all">
<title>Table 9: ABW_xCNTL register 605</title>
<tgroup cols="4">
<colspec colnum="1" colname="col1" colwidth="22mm"/>
<colspec colnum="2" colname="col2" colwidth="28mm"/>
<colspec colnum="3" colname="col3" colwidth="13mm"/>
<colspec colnum="4" colname="col4" colwidth="104mm"/>
<thead>
<row>
<entry valign="top"><b>Field</b></entry>
<entry valign="top"><b>Number of Bits</b></entry>
<entry valign="top"><b>Type</b></entry>
<entry valign="top"><b>Description</b></entry></row></thead>
<tbody>
<row>
<entry><b>ADDRM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry><b>Address range mask:</b><br/>
1 Address range selection field ADDRS is used<br/>
0 Address range selection is "don't care"</entry></row>
<row>
<entry><b>ADDRS</b></entry>
<entry>3</entry>
<entry>rw</entry>
<entry><b>Address range select:</b> 000 Address 1 OR address 2<br/>
001 Address 1 OR Above address 1<br/>
010 Address 2 OR Below address 2<br/>
011 Address 1 OR address 2 OR</entry></row>
<row>
<entry/>
<entry/>
<entry/>
<entry>Outside<br/>
100 Address 1 OR address 2 OR Inside<br/>
101 Reserved<br/>
110 Reserved<br/>
111 Reserved</entry></row><!-- EPO <DP n="35"> -->
<row>
<entry><b>BUSCONM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>Bus Control Mask<br/>
1 Break condition from <b>ABW_xBOS</b> is used<br/>
0 Break condition from <b>ABW_xBOS</b> is not used</entry></row>
<row>
<entry><b>BUSMASM</b></entry>
<entry>1</entry>
<entry>rw</entry>
<entry>Bus Master Mask<br/>
1 Break condition from <b>ABW_xGRNT</b> is used<br/>
0 Break condition from <b>ABW_xGRNT</b> is not used</entry></row>
<row>
<entry><b>REARM</b></entry>
<entry>1</entry>
<entry>w0</entry>
<entry><b>Rearms brk_out_x_n trigger:, xGNTT, xADRT and xBOST reset:</b> Write '1' to rearm, this bit always reads '0'.</entry></row>
<row>
<entry><b>Reserved</b></entry>
<entry>1</entry>
<entry/>
<entry/></row>
<row>
<entry><b>Reserved</b></entry>
<entry>2</entry>
<entry/>
<entry/></row>
<row>
<entry><b>Reserved</b></entry>
<entry>21</entry>
<entry/>
<entry/></row>
<row>
<entry><b>TRIG</b></entry>
<entry>1</entry>
<entry>r</entry>
<entry><b>State of brk_out_x_n trigger:</b> '1' armed / '0' fired, reset by writing to the RA bit.</entry></row></tbody></tgroup>
</table>
</tables></p>
<p id="p0097" num="0097">The foregoing description has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the invention to the precise form disclosed, and obviously many modifications and variations are possible in light of the disclosed teaching. The described embodiments were chosen in order to best explain the principles of the invention and its practical application to thereby enable others skilled in the art to best utilize the invention in various embodiments and with various<!-- EPO <DP n="36"> --> modifications as are suited to the particular use contemplated. It is intended that the scope of the invention be defined by the claims appended hereto.</p>
</description><!-- EPO <DP n="37"> -->
<claims id="claims01" lang="en">
<claim id="c-en-01-0001" num="0001">
<claim-text>Integrated circuit arrangement, comprising
<claim-text>• a plurality of circuit arrangement components,</claim-text>
<claim-text>• at least one coupler coupling the circuit arrangement components comprising, for each circuit arrangement component a computer bus (302-307) that is associated with the circuit arrangement component and via which the circuit arrangement component may be accessed wherein for each computer bus an address range may be set independently of the address ranges set for the other computer busses</claim-text>
<claim-text>• a coupler watcher (301) checking as to whether an access request to a circuit arrangement component has a request address, that identifies at least a part of the circuit arrangement component to which access is requested, that lies within the address range set for the computer bus associated with the circuit arrangement component to which the access is requested, and, dependent on whether the request address lies within the predetermined address range, the coupler watcher accepts the access request or generates a false access signal.</claim-text></claim-text></claim>
<claim id="c-en-01-0002" num="0002">
<claim-text>Integrated circuit arrangement as claimed in claim 1, the plurality of circuit arrangement components comprising at least one circuit arrangement component of a group selected from:
<claim-text>• volatile memory,</claim-text>
<claim-text>• non-volatile memory,</claim-text>
<claim-text>• memory controller,</claim-text>
<claim-text>• microprocessor,</claim-text>
<claim-text>• digital signal processor,</claim-text>
<claim-text>• system control logic,</claim-text>
<claim-text>• mobile radio communication module,</claim-text>
<claim-text>• crypto engine,</claim-text>
<claim-text>• serial interface,<!-- EPO <DP n="38"> --></claim-text>
<claim-text>• parallel interface,</claim-text>
<claim-text>• periphery component driver.</claim-text></claim-text></claim>
<claim id="c-en-01-0003" num="0003">
<claim-text>Integrated circuit arrangement as claimed in claim 1 or 2,<br/>
where at least one coupler comprising at least one data bus.</claim-text></claim>
<claim id="c-en-01-0004" num="0004">
<claim-text>Integrated circuit arrangement as claimed in any of claims 1 to 3,<br/>
the at least one coupler comprising at least one address bus.</claim-text></claim>
<claim id="c-en-01-0005" num="0005">
<claim-text>Integrated circuit arrangement as claimed in any of claims 1 to 4,<br/>
the coupler watcher comprising one or a plurality of address registers storing at least one address that forms the address range.</claim-text></claim>
<claim id="c-en-01-0006" num="0006">
<claim-text>Integrated circuit arrangement as claimed in any of claims 1 to 5,<br/>
the address range being a range selected from a group consisting of the following address ranges:
<claim-text>• an address range including all addresses that are higher than a predetermined address,</claim-text>
<claim-text>• an address range including all addresses that are equal to or higher than a predetermined address,</claim-text>
<claim-text>• an address range including all addresses that are lower than a predetermined address,</claim-text>
<claim-text>• an address range including all addresses that are equal to or lower than a predetermined address,</claim-text>
<claim-text>• an address range including all addresses that lie between a first predetermined address and a second predetermined address,</claim-text>
<claim-text>• an address range including all addresses that lie between a first predetermined address and a second predetermined address, including the first<!-- EPO <DP n="39"> --> predetermined address and the second predetermined address,</claim-text>
<claim-text>• an address range including all addresses that lie outside an address interval that is determined by a first predetermined address and a second predetermined address,</claim-text>
<claim-text>• an address range including all addresses that lie outside an address interval that is determined by a first predetermined address and a second predetermined address, including the first predetermined address and the second predetermined address.</claim-text></claim-text></claim>
<claim id="c-en-01-0007" num="0007">
<claim-text>Integrated circuit arrangement as claimed in any of claims 1 to 6,<br/>
the coupler watcher further checking as to whether an access request to one or a plurality of the circuit arrangement components has a request address that lies within another predetermined address range, and, dependent on whether the request address lies within the other predetermined address range, the coupler watcher generates an access interrupt signal for granting access to the circuit arrangement component.</claim-text></claim>
<claim id="c-en-01-0008" num="0008">
<claim-text>Integrated circuit arrangement as claimed in any of claims 1 to 7, further comprising<br/>
the false access signal being an access interrupt signal.</claim-text></claim>
<claim id="c-en-01-0009" num="0009">
<claim-text>Integrated circuit arrangement as claimed in any of claims 1 to 8, further comprising<br/>
a security controller denying the access to the circuit arrangement component in response to the response of the false access signal.</claim-text></claim>
<claim id="c-en-01-0010" num="0010">
<claim-text>Integrated circuit arrangement as claimed in claim 9,<!-- EPO <DP n="40"> --> the security controller re-setting the integrated circuit arrangement to a predetermined status, or generating an interrupt, or locking off access to a particular component.</claim-text></claim>
<claim id="c-en-01-0011" num="0011">
<claim-text>Integrated circuit arrangement as claimed in claim 10, the predetermined status being a new boot status.</claim-text></claim>
<claim id="c-en-01-0012" num="0012">
<claim-text>Method for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement, comprising a plurality of circuit arrangement components and at least one coupler coupling the circuit arrangement components, comprising, for each circuit arrangement component a computer bus (302-307) that is associated with the circuit arrangement component and via which the circuit arrangement<br/>
component may be accessed wherein for each computer bus an address range may be set independently of the address ranges set for the other computer busses, the method comprising:
<claim-text>• receiving (402) an access request to a circuit arrangement component,</claim-text>
<claim-text>• determining (403) a request address that identifies the at least a part of circuit arrangement component, to which access is requested,</claim-text>
<claim-text>• checking (404), by a common coupler watcher of the integrated circuit arrangement, as to whether the request address lies within the address range set for the computer bus associated with the circuit arrangement component to which the access is requested, and</claim-text>
<claim-text>• dependent on whether the request address lies within the predetermined address range, accepting the access request (406) or generating a false access signal.</claim-text><!-- EPO <DP n="41"> --></claim-text></claim>
<claim id="c-en-01-0013" num="0013">
<claim-text>Computer program product for monitoring access requests to an integrated circuit arrangement component of an integrated circuit arrangement, comprising a plurality of circuit arrangement components and at least one coupler coupling the circuit arrangement components, comprising, for each circuit arrangement component a computer bus (302-307) that is associated with the circuit arrangement component and via which the circuit arrangement component may be accessed wherein for each computer bus an address range may be set independently of the address ranges set for the other computer busses, the computer program product, when being executed by a processor, comprising:
<claim-text>• receiving (402) an access request to a circuit arrangement component,</claim-text>
<claim-text>• determining (403) a request address that identifies at least a part of the circuit arrangement component, to which access is requested,</claim-text>
<claim-text>• checking (404), by a common coupler watcher of the integrated circuit arrangement, as to whether the request address lies within the address range set for the computer bus associated with the circuit arrangement component to which the access is requested, and</claim-text>
<claim-text>• dependent on whether the request address lies within the predetermined address range, accepting the access request (406) or generating a false access signal.</claim-text></claim-text></claim>
</claims><!-- EPO <DP n="42"> -->
<claims id="claims02" lang="de">
<claim id="c-de-01-0001" num="0001">
<claim-text>Integrierte Schaltungs-Anordnung, aufweisend
<claim-text>• eine Mehrzahl von Schaltungs-Anordnungs-Komponenten,</claim-text>
<claim-text>• mindestens einen Koppler, der die Schaltungs-Anordnungs-Komponenten koppelt, aufweisend für jede Schaltungs-Anordnungs-Komponente einen Computer-Bus (302-307), der mit der Schaltungs-Anordnungs-Komponente verbunden ist und über welchen auf die Schaltungs-Anordnungs-Komponente zugegriffen werden kann, wobei für jeden Computer-Bus ein Adress-Bereich unabhängig von den für die anderen Computer-Busse gesetzten Adress-Bereichen gesetzt werden kann</claim-text>
<claim-text>• einen Koppler-Beobachter (301), der überprüft, ob eine Zugriffs-Anforderung auf eine Schaltungs-Anordnungs-Komponente eine Anforderungs-Adresse hat, die mindestens einen Teil der Schaltungs-Anordnungs-Komponente, auf die der Zugriff angefordert wird, identifiziert, die innerhalb des für den Computer-Bus, verbunden mit der Schaltungs-Anordnungs-Komponente, auf die Zugriff angefordert wird, gesetzten Adress-Bereichs liegt, und wobei, abhängig davon, ob die Anforderungs-Adresse innerhalb des vorgegebenen Adress-Bereichs liegt, der Koppler-Beobachter die Zugriffs-Anforderung akzeptiert oder ein Falscher-Zugriff-Signal erzeugt.</claim-text></claim-text></claim>
<claim id="c-de-01-0002" num="0002">
<claim-text>Integrierte Schaltungs-Anordnung wie in Anspruch 1 beansprucht,<br/>
wobei die Mehrzahl von Schaltungs-Anordnungs-Komponenten mindestens eine Schaltkreis-Anordnungs-Komponente enthält ausgewählt aus einer Gruppe von:
<claim-text>• flüchtigem Speicher,</claim-text>
<claim-text>• nicht-flüchtigem Speicher,</claim-text>
<claim-text>• Speicher-Steuerungseinrichtung,</claim-text>
<claim-text>• Mikroprozessor,</claim-text>
<claim-text>• Digital-Signal-Prozessor,<!-- EPO <DP n="43"> --></claim-text>
<claim-text>• System-Steuer-Logik,</claim-text>
<claim-text>• Mobilfunkkommunikationsmodul,</claim-text>
<claim-text>• Schlüssel-Engine,</claim-text>
<claim-text>• serieller Schnittstelle,</claim-text>
<claim-text>• paralleler Schnittstelle,</claim-text>
<claim-text>• Peripherie-Komponente-Treiber.</claim-text></claim-text></claim>
<claim id="c-de-01-0003" num="0003">
<claim-text>Integrierte Schaltungs-Anordnung wie in Anspruch 1 oder 2 beansprucht,<br/>
wobei mindestens ein Koppler mindestens einen Daten-Bus aufweist.</claim-text></claim>
<claim id="c-de-01-0004" num="0004">
<claim-text>Integrierte Schaltungs-Anordnung wie in irgendeinem der Ansprüche 1 bis 3 beansprucht,<br/>
wobei der mindestens eine Koppler mindestens einen Adress-Bus aufweist.</claim-text></claim>
<claim id="c-de-01-0005" num="0005">
<claim-text>Integrierte Schaltungs-Anordnung wie in irgendeinem der Ansprüche 1 bis 4 beansprucht,<br/>
wobei der Koppler-Beobachter aufweist ein oder eine Mehrzahl von Adress-Registern, die mindestens eine Adresse, die den Adress-Bereich bildet, speichern.</claim-text></claim>
<claim id="c-de-01-0006" num="0006">
<claim-text>Integrierte Schaltungs-Anordnung wie in irgendeinem der Ansprüche 1 bis 5 beansprucht,<br/>
wobei der Adress-Bereich ein Adress-Bereich ist ausgewählt aus einer Gruppe bestehend aus den folgenden Adress-Bereichen:
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die höher als eine vorgegebene Adresse sind,</claim-text>
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die gleich einer oder höher als eine vorgegebene(n) Adresse sind,</claim-text>
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die niedriger als eine vorgegebene Adresse sind,<!-- EPO <DP n="44"> --></claim-text>
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die gleich einer oder niedriger als eine vorgegebene Adresse sind,</claim-text>
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die zwischen einer ersten vorgegebenen Adresse und einer zweiten vorgegebenen Adresse liegen,</claim-text>
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die zwischen einer ersten vorgegebenen Adresse und einer zweiten vorgegebenen Adresse liegen, einschließlich der ersten vorgegebenen Adresse und der zweiten vorgegebenen Adresse,</claim-text>
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die außerhalb eines Adress-Bereichs, der bestimmt wird von einer ersten vorgegebenen Adresse und einer zweiten vorgegebenen Adresse, liegen,</claim-text>
<claim-text>• einem Adress-Bereich enthaltend alle Adressen, die außerhalb eines Adress-Bereichs, der bestimmt wird von einer ersten vorgegebenen Adresse und einer zweiten vorgegebenen Adresse, liegen, einschließlich der ersten vorgegebenen Adresse und der zweiten vorgegebenen Adresse.</claim-text></claim-text></claim>
<claim id="c-de-01-0007" num="0007">
<claim-text>Integrierte Schaltungs-Anordnung wie in irgendeinem der Ansprüche 1 bis 6 beansprucht,<br/>
wobei der Koppler-Beobachter ferner überprüft, ob eine Zugriffs-Anforderung auf eine oder eine Mehrzahl der Schaltungs-Anordnungs-Komponenten eine Anforderungs-Adresse hat, die innerhalb eines anderen vorgegebenen Adress-Bereichs liegt, und, abhängig davon, ob die Anforderungs-Adresse innerhalb des anderen vorgegebenen Adress-Bereichs liegt, der Koppler-Beobachter ein Zugriffs-Unterbrechungs-Signal zum Gewähren von Zugriff auf die Schaltungs-Anordnungs-Komponente erzeugt.</claim-text></claim>
<claim id="c-de-01-0008" num="0008">
<claim-text>Integrierte Schaltungs-Anordnung wie in irgendeinem der Ansprüche 1 bis 7 beansprucht, ferner aufweisend<!-- EPO <DP n="45"> --> das Falscher-Zugriff-Signal ein Zugriff-Unterbrechungs-Signal seiend.</claim-text></claim>
<claim id="c-de-01-0009" num="0009">
<claim-text>Integrierte Schaltungs-Anordnung wie in irgendeinem der Ansprüche 1 bis 8 beansprucht, ferner aufweisend<br/>
eine Sicherheits-Steuerungseinrichtung, die den Zugriff auf die Schaltungs-Anordnungs-Komponente in Antwort auf die Antwort des Falscher-Zugriff-Signals verweigert.</claim-text></claim>
<claim id="c-de-01-0010" num="0010">
<claim-text>Integrierte Schaltungs-Anordnung wie in Anspruch 9 beansprucht,<br/>
wobei die Sicherheits-Steuerungseinrichtung die integrierte Schaltungs-Anordnung auf einen vorgegebenen Status zurücksetzt oder eine Unterbrechung erzeugt oder den Zugriff zu einer bestimmten Komponente abschneidet.</claim-text></claim>
<claim id="c-de-01-0011" num="0011">
<claim-text>Integrierte Schaltungs-Anordnung wie in Anspruch 10 beansprucht,<br/>
wobei der vorgegebene Status ein Neu-Hochfahren-Status ist.</claim-text></claim>
<claim id="c-de-01-0012" num="0012">
<claim-text>Verfahren zum Überwachen von Zugriffs-Anforderungen auf eine integrierte Schaltungs-Anordnungs-Komponente einer integrierten Schaltungs-Anordnung, aufweisend eine Mehrzahl von Schaltungs-Anordnungs-Komponenten und mindestens einen Koppler, der die Schaltungs-Anordnungs-Komponenten koppelt, aufweisend, für jede Schaltungs-Anordnungs-Komponente einen Computer-Bus (302-307), der mit der Schaltungs-Anordnungs-Komponente verbunden ist und über welchen auf die Schaltungs-Anordnungs-Komponente zugegriffen werden kann, wobei für jeden Computer-Bus ein Adress-Bereich unabhängig von den für die anderen Computer-Busse gesetzten Adress-Bereichen gesetzt werden kann, das Verfahren aufweisend:
<claim-text>• Empfangen (402) einer Zugriffs-Anforderung auf eine Schaltkreis-Anordnungs-Komponente,<!-- EPO <DP n="46"> --></claim-text>
<claim-text>• Ermitteln (403) einer Anforderungs-Adresse, die den mindestens einen Teil der Schaltungs-Anordnungs-Komponente, zu der Zugriff angefordert wird, identifiziert,</claim-text>
<claim-text>• Überprüfen (404), durch einen gemeinsamen Koppler-Beobachter der integrierten Schaltungs-Anordnung, ob die Anforderungs-Adresse innerhalb des für den Computer-Bus, verbunden mit der Schaltungs-Anordnungs-Komponente, auf die der Zugriff angefordert wird, gesetzten Adress-Bereichs liegt, und</claim-text>
<claim-text>• abhängig davon, ob die Anforderungs-Adresse innerhalb des vorgegebenen Adress-Bereichs liegt, Akzeptieren der Zugriffs-Anforderung (406) oder Erzeugen eines Falscher-Zugriff-Signals.</claim-text></claim-text></claim>
<claim id="c-de-01-0013" num="0013">
<claim-text>Computer-Programm-Produkt zum Überwachen von Zugriffs-Anforderungen auf eine integrierte Schaltungs-Anordnungs-Komponente einer integrierten Schaltungs-Anordnung, aufweisend eine Mehrzahl von Schaltungs-Anordnungs-Komponenten und mindestens einen Koppler, der die Schaltungs-Anordnungs-Komponenten koppelt, aufweisend, für jede Schaltungs-Anordnungs-Komponente einen Computer-Bus (302-307), der mit der Schaltungs-Anordnungs-Komponente verbunden ist und über welchen auf die Schaltungs-Anordnungs-Komponente zugegriffen werden kann, wobei für jeden Computer-Bus ein Adress-Bereich unabhängig von den für die anderen Computer-Busse gesetzten Adress-Bereichen gesetzt werden kann, das Computer-Programm-Produkt, wenn es von einem Prozessor ausgeführt wird, aufweisend:
<claim-text>• Empfangen (402) einer Zugriffs-Anforderung auf eine Schaltkreis-Anordnungs-Komponente,</claim-text>
<claim-text>• Ermitteln (403) einer Anforderungs-Adresse, die mindestens einen Teil der Schaltungs-Anordnungs-Komponente, zu der Zugriff angefordert wird, identifiziert,<!-- EPO <DP n="47"> --></claim-text>
<claim-text>• Überprüfen (404), durch einen gemeinsamen Koppler-Beobachter der integrierten Schaltungs-Anordnung, ob die Anforderungs-Adresse innerhalb des für den Computer-Bus, verbunden mit der Schaltungs-Anordnungs-Komponente, auf die der Zugriff angefordert wird, gesetzten Adress-Bereichs liegt, und</claim-text>
<claim-text>• abhängig davon, ob die Anforderungs-Adresse innerhalb des vorgegebenen Adress-Bereichs liegt, Akzeptieren der Zugriffs-Anforderung (406) oder Erzeugen eines Falscher-Zugriff-Signals.</claim-text></claim-text></claim>
</claims><!-- EPO <DP n="48"> -->
<claims id="claims03" lang="fr">
<claim id="c-fr-01-0001" num="0001">
<claim-text>Agencement de circuit intégré comprenant
<claim-text>• une pluralité de composants d'agencement de circuit,</claim-text>
<claim-text>• au moins un coupleur couplant les composants d'agencement de circuit et comprenant, pour chaque composant d'agencement de circuit, un bus (302 à 307) d'ordinateur, qui est associé aux composants d'agencement de circuit et par lequel il peut être accédé aux composants d'agencement de circuit, dans lequel, pour chaque bus d'ordinateur, un domaine d'adresse peut être fixé indépendamment des domaines d'adresse fixés pour les autres bus d'ordinateur</claim-text>
<claim-text>• un veilleur (301) de coupleur contrôlant si une demande d'accès à un composant d'agencement de circuit a une adresse de demande qui identifie au moins une partie du composant d'agencement de circuit auquel l'accès est demandé, qui se trouve dans le domaine d'adresse fixé pour le bus d'ordinateur associé au composant d'agencement de circuit auquel l'accès est demandé et, suivant que l'adresse de demande se trouve dans le domaine d'adresse déterminé à l'avance, le veilleur de coupleur accepte la demande d'accès ou produit un faux signal d'accès.</claim-text></claim-text></claim>
<claim id="c-fr-01-0002" num="0002">
<claim-text>Agencement de circuit intégré suivant la revendication 1, la pluralité de composants d'agencement de circuit comprenant au moins un composant d'agencement de circuit d'un groupe choisi parmi :<!-- EPO <DP n="49"> -->
<claim-text>• mémoire volatile,</claim-text>
<claim-text>• mémoire non volatile,</claim-text>
<claim-text>• contrôleur de mémoire,</claim-text>
<claim-text>• microprocesseur,</claim-text>
<claim-text>• processeur numérique de signal,</claim-text>
<claim-text>• logique de commande de système,</claim-text>
<claim-text>• module de communication par téléphonie mobile,</claim-text>
<claim-text>• moteur de chiffrement,</claim-text>
<claim-text>• interface série,</claim-text>
<claim-text>• interface parallèle,</claim-text>
<claim-text>• circuit d'attaque de composants en périphérie.</claim-text></claim-text></claim>
<claim id="c-fr-01-0003" num="0003">
<claim-text>Agencement de circuit intégré suivant la revendication 1 ou 2,<br/>
dans lequel au moins un coupleur comprend au moins un bus de données.</claim-text></claim>
<claim id="c-fr-01-0004" num="0004">
<claim-text>Agencement de circuit intégré suivant l'une ou quelconque des revendications 1 à 3,<br/>
dans lequel le au moins un coupleur comprend au moins un bus d'adresse.</claim-text></claim>
<claim id="c-fr-01-0005" num="0005">
<claim-text>Agencement de circuit intégré suivant l'une ou quelconque des revendications 1 à 4,<br/>
dans lequel le veilleur de coupleur comprend au moins un ou une pluralité de registres d'adresse, mémorisant au moins une adresse qui forme le domaine d'adresse.</claim-text></claim>
<claim id="c-fr-01-0006" num="0006">
<claim-text>Agencement de circuit intégré suivant l'une ou quelconque des revendications 1 à 5,<br/>
le domaine d'adresse étant un domaine choisi dans un groupe consistant en les domaines d'adresse suivants :
<claim-text>• un domaine incluant toutes les adresses qui sont supérieures à une adresse déterminée à l'avance,<!-- EPO <DP n="50"> --></claim-text>
<claim-text>• un domaine d'adresse comprenant toutes les adresses qui sont supérieures ou égales à une adresse déterminée à l'avance,</claim-text>
<claim-text>• un domaine d'adresse incluant toutes les adresses qui sont plus petites qu'une adresse déterminée à l'avance,</claim-text>
<claim-text>• un domaine d'adresse incluant toutes les adresses qui sont inférieures ou égales à une adresse déterminée à l'avance,</claim-text>
<claim-text>• un domaine d'adresse incluant toutes les adresses qui se trouvent entre une première adresse déterminée à l'avance et une deuxième adresse déterminée à l'avance,</claim-text>
<claim-text>• un domaine d'adresse incluant toutes les adresses qui se trouvent entre une première adresse déterminée à l'avance et une deuxième adresse déterminée à l'avance, y compris la première adresse déterminée à l'avance et la deuxième adresse déterminée à l'avance,</claim-text>
<claim-text>• un domaine d'adresse incluant toutes les adresses qui se trouvent à l'extérieur d'un intervalle d'adresse qui est déterminé par une première adresse déterminée à l'avance et par une deuxième adresse déterminée à l'avance,</claim-text>
<claim-text>• un domaine d'adresse incluant toutes les adresses qui se trouvent à l'extérieur d'un intervalle d'adresse qui est déterminé par une première adresse déterminée à l'avance et par une deuxième adresse déterminée à l'avance, y compris la première adresse déterminée à l'avance et la deuxième adresse déterminée à l'avance.</claim-text></claim-text></claim>
<claim id="c-fr-01-0007" num="0007">
<claim-text>Agencement de circuit intégré suivant l'une ou quelconque des revendications 1 à 6,<br/>
le veilleur de coupleur contrôlant, en outre, si une demande d'accès à l'un ou à plusieurs des composants de l'agencement de circuit a une adresse de demande qui se trouve dans un autre domaine d'adresse déterminé à l'avance, et, selon que l'adresse de demande se trouve dans l'autre domaine d'adresse déterminé à l'avance, le veilleur de coupleur produit un<!-- EPO <DP n="51"> --> signal d'interruption d'accès pour accorder accès au composant d'agencement de circuit.</claim-text></claim>
<claim id="c-fr-01-0008" num="0008">
<claim-text>Agencement de circuit intégré suivant l'une ou quelconque des revendications 1 à 7, comprenant en outre le fait<br/>
que le faux signal d'accès est un signal d'interruption d'accès.</claim-text></claim>
<claim id="c-fr-01-0009" num="0009">
<claim-text>Agencement de circuit intégré suivant l'une ou quelconque des revendications 1 à 8, comprenant en outre<br/>
un dispositif de commande de sécurité déniant l'accès au composant d'agencement de circuit en réaction à la réaction du faux signal d'accès.</claim-text></claim>
<claim id="c-fr-01-0010" num="0010">
<claim-text>Agencement de circuit intégré suivant la revendication 9,<br/>
dans lequel le dispositif de commande de sécurité remet l'agencement de circuit intégré à un statut déterminé à l'avance ou produit une interruption ou un verrouillage d'accès à un composant particulier.</claim-text></claim>
<claim id="c-fr-01-0011" num="0011">
<claim-text>Agencement de circuit intégré suivant la revendication 10,<br/>
dans lequel le statut déterminé à l'avance est un nouveau statut d'amorçage.</claim-text></claim>
<claim id="c-fr-01-0012" num="0012">
<claim-text>Procédé de contrôle de demande d'accès à un composant d'agencement de circuit intégré d'un agencement de circuit intégré, comprenant une pluralité de composants d'agencement de circuit et au moins un coupleur couplant les composants d'agencement de circuit, comprenant, pour chaque composant d'agencement de circuit, un bus (302 à 307) d'ordinateur, qui est associé au composant d'agencement de circuit et par lequel il peut être accédé au composant d'agencement de circuit, dans lequel, pour chaque bus d'ordinateur, un domaine d'adresse peut être fixé indépendamment des domaines d'adresse fixés pour les autres bus d'ordinateur, procédé dans lequel :<!-- EPO <DP n="52"> -->
<claim-text>• on reçoit (402) une demande d'accès à un composant d'agencement de circuit,</claim-text>
<claim-text>• on détermine (403) une adresse de demande, qui identifie la au moins une partie d'un composant d'agencement de circuit auquel l'accès est demandé,</claim-text>
<claim-text>• on contrôle (404), par un veilleur commun de coupleur de l'agencement de circuit intégré, si l'adresse de demande se trouve dans le domaine d'adresse fixé pour le bus d'ordinateur associé au composant de l'agencement de circuit auquel l'accès est demandé, et</claim-text>
<claim-text>• suivant que l'adresse de demande se trouve dans le domaine d'adresse déterminé à l'avance, on accepte la demande (406) d'accès ou on produit un faux signal d'accès.</claim-text></claim-text></claim>
<claim id="c-fr-01-0013" num="0013">
<claim-text>Produit de programme informatique pour contrôler des demandes d'accès à un composant d'agencement de circuit intégré d'un agencement de circuit intégré, comprenant une pluralité de composants d'agencement de circuit et au moins un coupleur couplant les composants d'agencement de circuit, comprenant, pour chaque composant d'agencement de circuit, un bus (302 à 307) d'ordinateur, qui est associé au composant d'agencement du circuit et par lequel il peut être accédé au composant d'agencement, dans lequel, pour chaque bus d'ordinateur, un domaine d'adresse peut être fixé indépendamment des domaines d'adresse fixés pour les autres bus d'ordinateur, le produit de programme informatique, lorsqu'il est exécuté par un processeur comprenant les stades dans desquels
<claim-text>• on reçoit (402) une demande d'accès à un composant d'agencement de circuit,</claim-text>
<claim-text>• on détermine (403) une adresse de demande qui identifie la au moins une partie d'un composant d'agencement de circuit auquel l'accès est demandé,</claim-text>
<claim-text>• on contrôle (404), par un veilleur commun de coupleur de<!-- EPO <DP n="53"> --> l'agencement de circuit intégré, si l'adresse de demande se trouve dans le domaine d'adresse fixé pour le bus d'ordinateur associé au composant de l'agencement de circuit auquel l'accès est demandé, et</claim-text>
<claim-text>• suivant que l'adresse de demande se trouve dans le domaine d'adresse déterminé à l'avance, on accepte la demande (406) d'accès ou on produit un faux signal d'accès.</claim-text></claim-text></claim>
</claims>
<drawings id="draw" lang="en">
<figure id="f0001" num="1"><img id="if0001" file="imgf0001.tif" wi="165" he="220" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="54"> -->
<figure id="f0002" num="2"><img id="if0002" file="imgf0002.tif" wi="165" he="133" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="55"> -->
<figure id="f0003" num="3"><img id="if0003" file="imgf0003.tif" wi="165" he="129" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="56"> -->
<figure id="f0004" num="4"><img id="if0004" file="imgf0004.tif" wi="165" he="170" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="57"> -->
<figure id="f0005" num="5"><img id="if0005" file="imgf0005.tif" wi="165" he="195" img-content="drawing" img-format="tif"/></figure><!-- EPO <DP n="58"> -->
<figure id="f0006" num="6"><img id="if0006" file="imgf0006.tif" wi="165" he="188" img-content="drawing" img-format="tif"/></figure>
</drawings>
<ep-reference-list id="ref-list">
<heading id="ref-h0001"><b>REFERENCES CITED IN THE DESCRIPTION</b></heading>
<p id="ref-p0001" num=""><i>This list of references cited by the applicant is for the reader's convenience only. It does not form part of the European patent document. Even though great care has been taken in compiling the references, errors or omissions cannot be excluded and the EPO disclaims all liability in this regard.</i></p>
<heading id="ref-h0002"><b>Patent documents cited in the description</b></heading>
<p id="ref-p0002" num="">
<ul id="ref-ul0001" list-style="bullet">
<li><patcit id="ref-pcit0001" dnum="US5754762A"><document-id><country>US</country><doc-number>5754762</doc-number><kind>A</kind></document-id></patcit><crossref idref="pcit0001">[0005]</crossref></li>
<li><patcit id="ref-pcit0002" dnum="US6047388A"><document-id><country>US</country><doc-number>6047388</doc-number><kind>A</kind></document-id></patcit><crossref idref="pcit0002">[0006]</crossref></li>
<li><patcit id="ref-pcit0003" dnum="DE19502626A1"><document-id><country>DE</country><doc-number>19502626</doc-number><kind>A1</kind></document-id></patcit><crossref idref="pcit0003">[0007]</crossref></li>
</ul></p>
</ep-reference-list>
</ep-patent-document>
