Multi-world Hardware Isolation System IP for System Security
Delivers advanced execution environment capabilities and hardware-enforced isolation to RISC-V systems
Overview
SiFive WorldGuard delivers advanced execution environment capabilities and hardware-enforced isolation to RISC-V systems. As a core component of the broader SiFive Shield open standard security architecture, WorldGuard provides comprehensive memory protection and access control. This scalable framework replaces closed proprietary architectures, ensuring core security and data flow integrity for complex SoCs.
Challenge
Modern SoCs integrate numerous shared resources, from multi-core CPUs to advanced DMA engines. Without precise isolation, untrusted applications can hijack peripherals or manipulate shared memory. Legacy systems relying on binary secure states struggle to efficiently partition concurrent tasks, creating software overhead and security risks.
Solution
WorldGuard provides a highly scalable, process-driven isolation engine. Currently being standardized as the official RISC-V Worlds architecture, it tracks a World ID (WID) for every transaction. Hardware wgCheckers and wgMarkers enforce access rights directly at the destination resource.
Impact
This architecture provides direct, hardware-enforced separation of operating systems and trusted applications, removing hypervisor bottlenecks. Upcoming ISA extensions help teams build modular products with reduced complexity. Chip designers empower RISC-V SoCs to achieve unprecedented security, ecosystem compatibility, and high-throughput performance.
ARCHITECTURAL HIGHLIGHTS
Privilege Mode Mapping
WorldGuard isolates domains both horizontally and vertically. It maps World IDs (WIDs) to RISC-V privilege modes to a separate security monitor from operating systems and applications. This architecture serves as the blueprint for the official RISC-V Worlds standard, establishing strict access boundaries across the entire core complex.
System-Level Filtering
Dedicated wgMarkers append WIDs to all transactions from CPUs and bus masters. These tags propagate across the interconnect to localized wgCheckers, which filter resource requests against authorized access lists. This hardware-level enforcement ensures deterministic performance without the software aliasing overhead required by legacy systems.
TrustZone Emulation
While WorldGuard scales up to 32 distinct execution worlds for advanced multi-tenant isolation, it also accommodates legacy transitions. Developers can utilize a 1-bit WID configuration to perfectly emulate TrustZone environments, simplifying software migration while securing a pathway to next-generation SoC designs.
SUMMARY
SiFive WorldGuard redefines SoC domain separation as the foundational architecture for the RISC-V Worlds standard. This scalable, multi-world alternative to restrictive binary legacy security enables seamless multi-tenant environments. It safeguards critical memory, cache allocation, and shared peripherals entirely in hardware. Isolating tasks across distinct domains gives developers the granular control needed to build safe, compliant automotive, datacenter, and edge systems. WorldGuard is a key component of SiFive Shield, a robust collection of security features available with SiFive processor IP
Key features
- Multi-World Support: Hardware enforced separation scaling up to 32 distinct execution worlds.
- System-Wide Tracking: Dedicated wgMarkers append World IDs to transactions from CPUs and bus masters.
- Distributed Enforcement: Localized wgCheckers filter resource requests against authorized WID access rules.
- Privilege Mapping: Maps WIDs directly to RISC-V Machine, Supervisor, and User execution modes.
- Flexible for Familiarity: Can easily be configured down to just 2 worlds (zones) to replicate legacy secure environments.
- Open Standard Leadership: Serves as the foundational architecture for the official RISC-V Worlds standard.
- ISA Alignment: Implements proposed Smwg, Smwgd, and Sswg extensions for broad ecosystem compatibility.
- Comprehensive Resource Control: Extends hardware isolation policies directly to debug interfaces, trace modules, performance counters, and micro-architectural mechanisms.
Block Diagram
Applications
- Automotive ECUs
- Trusted Execution Environments
- Complex SoCs
Specifications
Identity
Files
Note: some files may require an NDA depending on provider policy.
Provider
Learn more about Root Of Trust IP core
Root of Trust: A Security Essential for Cyber Defense
Tailoring Root Of Trust Security Capabilities To Specific Customer Needs
Rambus CryptoManager Root of Trust Solutions Tailor Security Capabilities to Specific Customer Needs with New Three-Tier Architecture
Rambus RT-660 Root of Trust IP Achieves FIPS 140-3 Certification
Extending Security IP leadership with FIPS 140-2 CMVP Certification for Root of Trust IP
Frequently asked questions about Root of Trust IP cores
What is Multi-world Hardware Isolation System IP for System Security?
Multi-world Hardware Isolation System IP for System Security is a Root Of Trust IP core from Sifive, Inc. listed on Semi IP Hub.
How should engineers evaluate this Root Of Trust?
Engineers should review the overview, key features, supported foundries and nodes, maturity, deliverables, and provider information before shortlisting this Root Of Trust IP.
Can this semiconductor IP be compared with similar products?
Yes. Buyers can compare this product with similar semiconductor IP cores or IP families based on category, provider, process options, and structured technical specifications.