system on chip
By introducing a security module and encryption/decryption mechanism into the system-on-chip, the problem of limited internal memory capacity of the SoC is solved, enabling secure access and management of non-volatile memory, and enhancing the system's security and data protection capabilities.
Patent Information
- Application Number
- CN202010707672.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-08-05
- Filing Date
- 2020-07-21
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2040-07-21
AI Technical Summary
Existing System-on-Chip (SoC) systems are vulnerable to attack due to limited internal memory capacity, difficulty in securely accessing and managing non-volatile memory, and lack of effective secure storage and data encryption mechanisms.
A system-on-a-chip (SoC) was designed, comprising a security module, a host controller, shared memory, and an encryption/decryption module. The security controller monitors log data, non-volatile memory stores security parameters, and the encryption/decryption module enables secure data transmission and storage, ensuring the security and integrity of the system.
It improves the security level of the on-chip system, prevents hacker intrusion, ensures data confidentiality and integrity, and enables secure access and management of external memory.
Smart Images

Figure CN112329074B_ABST
Abstract
Description
[0001] Cross-reference to related applications
[0002] This application claims priority to Korean Patent Application No. 10-2019-0094941, filed on August 5, 2019, with the Korean Intellectual Property Office, the entire disclosure of which is incorporated herein by reference. Technical Field
[0003] Embodiments of this disclosure relate to systems-on-chip, and more specifically to systems-on-chip in which a non-volatile memory manager securely accesses non-volatile memory. Background Technology
[0004] An application processor (AP) can be implemented as a System-on-a-Chip (SoC), which integrates various systems. Because the SoC integrates various systems, the capacity of its internal memory (such as static random access memory (SRAM)) may be limited. To compensate for the limited internal memory size, the SoC can be coupled with external memory devices.
[0005] In addition, the SoC may include a secure element that provides security features and secure storage locations for the SoC. The secure element can operate by utilizing code or data stored in the SoC's internal memory or external memory. Summary of the Invention
[0006] This disclosure provides an on-chip system including a non-volatile memory and a non-volatile memory manager for providing secure access to secure data.
[0007] According to one aspect of the embodiments, a system-on-a-chip (SoC) is provided, comprising: a security module configured to receive power from a first power module; a host controller configured to control data transmission between the SoC and an external device; and a shared memory configured to store log data under the control of the host controller, wherein the host controller and the shared memory are configured to receive power from a second power module; the security module includes: a security controller configured to monitor the log data stored in the shared memory to determine whether a security attack has occurred in the SoC, and to provide a signal indicating a security attack to the host controller based on the determination that a security attack has occurred; a first memory configured to store security parameters, the security parameters including an encryption key and a timestamp; and an encryption / decryption module configured to receive the security parameters from the first memory and, under the control of the security controller, encrypt or decrypt data transmitted between the SoC and the external device based on the security parameters, wherein the shared memory and the first memory are non-volatile memories.
[0008] According to an aspect of an embodiment, there is provided a system-on-chip including: a security module configured to receive power from a first power module; a host controller; a shared memory configured to store log data under control of the host controller, the shared memory and the host controller configured to receive power from a second power module; an interface through which data is transmitted between the system-on-chip and a plurality of electronic devices; and the security module including: a security controller configured to monitor the log data stored in the shared memory for determining whether a security attack has occurred in the system-on-chip, and to provide a signal indicating the security attack to the host controller based on a determination that the security attack has occurred; a first memory configured to store a security parameter; a first memory manager configured to control access to the first memory and transmission of the data transmitted between the system-on-chip and the plurality of electronic devices under control of the security controller; a second memory configured to store the security parameter; and an encryption / decryption module configured to receive the security parameter from the first memory or the second memory to encrypt the data transmitted between the system-on-chip and the plurality of electronic devices or to decrypt encrypted data.
[0009] According to an aspect of an embodiment, there is provided a system-on-chip including: a security module; a first power module configured to control power provided to the security module; a host controller; a shared memory configured to store log data under control of the host controller; an interface through which data is transmitted between the system-on-chip and a plurality of electronic devices; and a second power module configured to control power provided to the host controller and the shared memory. And the security module including: a security controller configured to monitor the log data stored in the shared memory for determining whether a security attack has occurred in the system-on-chip, and to provide a signal indicating the security attack to the host controller based on a determination that the security attack has occurred; a first memory configured to store a security parameter; a first memory manager configured to control access to the first memory and transmission of the data transmitted between the system-on-chip and the plurality of electronic devices under control of the security controller; a second memory configured to store the security parameter; an encryption / decryption module configured to receive the security parameter from the first memory or the second memory to encrypt the data transmitted between the system-on-chip and the plurality of electronic devices or to decrypt encrypted data.
[0010] However, aspects of the present disclosure are not limited to what is described herein but extend to whatever falls within the scope of the appended claims. The above and other aspects of the present disclosure will become more apparent by describing in detail our embodiments thereof, taken in conjunction with the accompanying drawings, given by way of illustration. BRIEF DESCRIPTION OF DRAWINGS
[0011] The above and other aspects of the present disclosure will become more apparent by describing in detail our embodiments thereof, taken in conjunction with the accompanying drawings, given by way of illustration.
[0012] Figure 1 is a block diagram illustrating a system on chip according to embodiments of the present disclosure;
[0013] Figure 2 is a diagram illustrating a memory region of a system on chip according to embodiments of the present disclosure;
[0014] Figure 3 is a block diagram illustrating an external memory connected to a system on chip according to embodiments of the present disclosure;
[0015] Figure 4 is a block diagram illustrating an external memory connected to a system on chip according to embodiments of the present disclosure;
[0016] Figure 5 is a diagram illustrating a method of storing encrypted data in an external memory of a system on chip according to embodiments of the present disclosure;
[0017] Figure 6 is a flowchart illustrating a method of storing encrypted data in an external memory;
[0018] Figure 7 is a block diagram illustrating a method of reading encrypted data or encrypted code stored in an external memory in a system on chip according to embodiments of the present disclosure;
[0019] Figure 8 is a flowchart illustrating a method of reading encrypted data or encrypted code stored in an external memory;
[0020] Figure 9 is a block diagram illustrating a system on chip according to embodiments of the present disclosure;
[0021] Figure 10 is a block diagram illustrating a system on chip according to embodiments of the present disclosure;
[0022] Figure 11 is a block diagram illustrating a system on chip according to embodiments of the present disclosure;
[0023] Figure 12 is a block diagram illustrating a shared memory of a system on chip according to embodiments of the present disclosure;
[0024] Figure 13 is a block diagram illustrating a monitoring function of a system on chip according to embodiments of the present disclosure; and
[0025] Figure 14 is a block diagram illustrating a system on chip according to embodiments of the present disclosure. DETAILED DESCRIPTION
[0026] Figure 1is a block diagram illustrating a system on chip according to an embodiment of the disclosure.
[0027] Referring to Figure 1 According to an embodiment of the disclosure, the system on chip 300 can include a security module 100 and a normal module 200.
[0028] The security module 100 can include a security controller 110, a first memory manager 130, a first memory 140, an encryption / decryption module 150, a random access memory (RAM) 170, a read only memory (ROM) 175, an encryption engine 180, a physically unclonable function 190 (physically unclonable object), and a random number generator 195. The security controller 110, the first memory manager 130, the encryption / decryption module 150, the RAM 170, the ROM 175, the encryption engine 180, the physically unclonable function 190, and the random number generator 195 can be connected to each other through at least one first bus 120.
[0029] The security controller 110 can be connected to the first bus 120 to control the overall operation of the security module 100. The security controller 110 can provide an isolated execution environment for independently performing a security operation without interference from the normal module 200.
[0030] The first memory manager 130 can include a buffer unit 132 and a timestamp manager 134. The buffer unit 132 can store data according to a write command of the security controller 110. The timestamp manager 134 can control a timestamp of data stored in the first memory 140.
[0031] The physically unclonable function 190 and the random number generator 195 can generate a security parameter. The physically unclonable function 190 or the random number generator 195 can generate a security parameter and inject the security parameter into the first memory 140.
[0032] The first memory 140 can store a security parameter. The security parameter can include an encryption key and a timestamp.
[0033] The first memory 140 can not be directly connected to the first bus 120, but can be directly connected to the first memory manager 130. The first memory 140 can not be directly accessed by the security controller 110, and can be directly accessed by the first memory manager 130. That is, the security controller 110 can not independently read and write data stored in the first memory 140 without the control of the first memory manager 130.
[0034] Accordingly, since the secure controller 110 cannot access the first memory 140 even if the secure controller 110 is hacked, the secure parameter can be safely stored and the security level of the normal module 200 can be improved.
[0035] The first memory 140 can include, for example, a non-volatile memory (NVM).
[0036] The encryption / decryption module 150 can include an encryptor / decryptor 152 and a hash 154.
[0037] The encryptor / decryptor 152 can perform an encryption operation on the secure data transmitted from the secure processor 110 using the secure parameter according to an encryption algorithm. The encryptor / decryptor 152 can perform a decryption operation on the encrypted data transmitted from the external memory 400 and the external memory 500.
[0038] The encryption algorithm can be AES (Advanced Encryption Standard), DES (Data Encryption Standard), Triple DES, SEED, HIGHT (High Security and Light Weight), ARIA, LEA (Lightweight Encryption Algorithm), etc. Also, for example, the encryption algorithm can perform an encryption operation in a block encryption mode. The block encryption mode can be an ECB (Electronic Code Book) mode, a CBC (Cipher Block Linking) mode, a CTR mode, a PCBC (Propagating Cipher Block Linking) mode, a CFB (Cipher Feedback) mode, etc.
[0039] The hash 154 can calculate a message authentication code (MAC) using the secure parameter. The hash 154 can calculate the message authentication code using a hash-based message authentication code (HMAC) algorithm, a cipher-based message authentication code (CMAC) algorithm, etc.
[0040] The encryption / decryption module 150 can output encrypted data including the encrypted secure data and the message authentication code.
[0041] The RAM (Random Access Memory) 170 can temporarily store secure data, secure code, etc. The RAM 170 can receive encrypted code on the fly from the first external memory 4000. The secure data, the secure code, or the encrypted code stored in the RAM 170 can be executed by the secure controller 110.
[0042] The ROM (Read Only Memory) 175 can store secure data, secure code, etc. in a non-volatile manner. The ROM 175 can store data, etc. required for the secure module 100 to perform a secure operation. The secure data or the secure code stored in the ROM 175 can be executed by the secure controller 110.
[0043] The encryption engine 180 can be connected to the bus 120. The encryption engine 180 can encrypt data stored in the memories 170 and 175 inside the secure module 100.
[0044] The normal module 200 can include a host controller 210, a mailbox 230, a shared memory 240, a first external memory controller 250, a second external memory controller 260, an interface 270, and other modules 280. The host controller 210, the mailbox 230, the shared memory 240, the first external memory controller 250, the second external memory controller 260, the interface 270, and the modules 280 can be connected to each other through at least one second bus 220.
[0045] The first bus 120 and the second bus 220 can provide a data input / output path, a command path, etc.
[0046] The host controller 210 can be connected to the second bus 220 to control the operation of the normal module 200. The host controller 210 can communicate with the secure controller 110 through the mailbox 230.
[0047] The shared memory 240 can store data required for the operation of the host module 210. The host controller 210 and the secure controller 110 can communicate with each other through the shared memory 240.
[0048] The shared memory 240 can include, for example, a non-volatile memory (NVM).
[0049] Due to a limited internal storage capacity of the system on chip 300, a limited area of the system on chip 300, etc., the system on chip 300 can be connected to the first external memory 400 and the second external memory 500.
[0050] The first external controller 250 and the second external controller 260 can provide encrypted data provided from the secure module 100 to the first external memory 400 or the second external memory 500. The first external controller 250 and the second external controller 260 can provide encrypted data or encrypted code stored in the first external memory 400 or the second external memory 500 to the secure module 100.
[0051] The normal module 200 can include various modules 280 for driving the system on chip 300.
[0052] The electronic device 600 can be connected to the system on chip 300 through the interface 270. The electronic device 600 can include, for example, a display, an image sensor, etc. that communicate with the system on chip 300.
[0053] A system on chip according to embodiments of the disclosure, for example, can be included in, but is not limited to, one of the following: a server, a computer, a smartphone, a tablet, a personal digital assistant (PDA), a digital camera, a portable multimedia player (PMP), a wearable device, an Internet of Things (IoT) device, etc.
[0054] Figure 2 is a block diagram illustrating a memory region of a system on chip according to embodiments of the disclosure.
[0055] Referring to Figure 1 and Figure 2 , the memory region can include a normal region 1000 of level 0, a trust zone region 1200 of level 1, a shared region 1400 of level 2, an encrypted region 1600 of level 3, and a secure parameter region 1800 of level 4. A firewall can be arranged between the respective memory regions. Each level can indicate a security level.
[0056] The normal region 1000 can be a region accessed by the normal module 200 in a normal mode.
[0057] The trust zone region 1200 can be a region written and read by the normal module 200 in a secure mode. The trust zone region 1200 can be, for example, a TEE (Trusted Execution Environment) region.
[0058] The shared region 1400 can be a region writable by the normal module 200 in a secure mode but not readable by it, and the shared region 1400 is accessed by the secure module 100. Log data can be stored in the shared region 1400.
[0059] The encrypted region 1600 can be a region accessed by the secure module 100 through the encryption / decryption module 150. Encrypted data or encrypted code can be stored in the encrypted region 1600. Alternatively, for example, encrypted non-volatile data can be stored.
[0060] The secure parameter region 1800 can be a region accessed only by the first memory manager 130. An encryption key and a time stamp can be stored in the secure parameter region 1800.
[0061] Figure 3 is a block diagram illustrating a first external memory connected to a system on chip according to embodiments of the disclosure.
[0062] Referring to Figure 3 , the first external memory 400 can include the normal region 1000, the trust zone region 1200, and the encrypted region 1600. In addition, the first external memory 400 can further include the shared region 1400.
[0063] The encrypted area 1600 can correspond to an area that the secure module 100 can access through the encryption / decryption module 150. An attacker can probe or observe data of the secure module 100 and the first external memory 400.
[0064] Accordingly, the secure module 100 and the first external memory 400 can transmit and receive encrypted data or encrypted code, and encrypted data or encrypted code required for the operation of the secure module 100 can be stored in the encrypted area 1600. That is, an attacker can obtain only encrypted data and code, and can not know data and code before encryption.
[0065] The first external memory 400 can include, for example, a DRAM memory.
[0066] Figure 4 is a block diagram illustrating a second external memory connected to a system on chip according to an embodiment of the disclosure. It will be mainly described that the second external memory 500 is different from the first external memory 400 of Figure 3 is a block diagram illustrating a second external memory connected to a system on chip according to an embodiment of the disclosure. It will be mainly described that the second external memory 500 is different from the first external memory 400 of
[0067] Referring to Figure 4 , the second external memory 500 can include a normal area 1000, a trust zone area 1200, and an encrypted area 1600. In addition, the second external memory 500 can further include a shared area 1400.
[0068] The secure module 100 and the second external memory 500 can transmit and receive encrypted data or encrypted code, and encrypted data or encrypted code required for the operation of the secure module 100 can be stored in the encrypted area 1600.
[0069] The second external memory 500 can include, for example, a flash memory. The encrypted area 1600 of the second external memory 500 can further store encrypted non-volatile data that needs to be stored even if the system on chip is powered off.
[0070] Figure 5 is a block diagram illustrating a method of storing encrypted data in an external memory of a system on chip according to an embodiment of the disclosure. Figure 6 is a flowchart illustrating a method of storing encrypted data in an external memory.
[0071] Referring to Figure 5 and Figure 6 The secure controller 110 can issue a secure data write command W to the first memory manager 130 (S100).
[0072] The first memory manager 130 can transfer the secure data to the encrypter 140. The first memory manager 130 can access the secure parameters (key, timestamp) stored in the first memory 140. The first memory manager 130 can control the first memory 140 to transfer the secure data (data) and the secure parameters (key, timestamp) to the encryption / decryption module 150.
[0073] When the timestamp manager 134 provides the Nth timestamp to the encryption / decryption module 150, the timestamp manager 134 can generate an (N+1)th timestamp.
[0074] The encrypter / decrypter 152 encrypts the secure data (data) using the secure parameters (key, timestamp), and the hash 154 can calculate a message authentication code MAC using the secure parameters (S120).
[0075] The encryption / decryption module 150 can generate encrypted data including the encrypted secure data and the message authentication code (S140). The encrypted data can be, for example, in a form in which the secure data and the message authentication code are merged, or can be in a form in which the secure data and the message authentication code are mixed.
[0076] The encryption / decryption module 150 can transfer the encrypted data to the first external memory controller 250 or the second external memory controller 260.
[0077] The first external memory controller 250 can transfer the encrypted data to the first external memory 400, and the encrypted data can be stored in the first external memory 400.
[0078] The second external memory controller 260 can transfer the encrypted data to the second external memory 500, and the encrypted data can be stored in the second external memory 500 (S160). Accordingly, the confidentiality and integrity of the secure data or the secure code can be maintained.
[0079] Figure 7 is a block diagram illustrating a method for reading encrypted data or encrypted code stored in an external memory in a system on chip according to an embodiment of the disclosure. Figure 8 is a flowchart illustrating a method of reading encrypted data or encrypted code stored in an external memory.
[0080] Reference Figure 7 and Figure 8 The secure controller 110 can issue a read command R with respect to the encrypted data or the encrypted code stored in the first external memory 400 or the second external memory 500 (S200).
[0081] The first external memory controller 250 can transfer the encrypted data or encrypted code stored in the first external memory 400 to the encryption / decryption module 150. Alternatively, the second external memory controller 260 can transfer the encrypted data or encrypted code stored in the second external memory 500 to the encryption / decryption module 150 (S220).
[0082] The first memory manager 130 can access the security parameters (key, timestamp) stored in the first memory 140. The first memory manager 130 can control the first memory 140 to transfer the security parameters (key, timestamp) to the encryption / decryption module 150.
[0083] The encryptor / decryptor 152 can decrypt the encrypted data or encrypted code using the security parameters, and output the secure data or secure code and the message authentication code MAC1.
[0084] The hash 154 can calculate the message authentication code MAC2 using the security parameters provided from the first memory 140.
[0085] The encryption / decryption module 150 can compare the message authentication code MAC1 decrypted from the encrypted data or encrypted code with the message authentication code MAC2 calculated by the hash 154.
[0086] When the message authentication code MAC1 decrypted from the encrypted data or encrypted code is the same as the message authentication code MAC2 calculated by the hash 154, the encryption / decryption module 150 can transfer the secure data or secure code to the security controller 110.
[0087] When the message authentication code MAC1 decrypted from the encrypted data or encrypted code is not the same as the message authentication code MAC2 calculated from the hash 154, the encryption / decryption module 150 can terminate the reading of the secure data or secure code. Accordingly, the confidentiality and integrity of the secure data or secure code can be maintained.
[0088] Figure 9 is a block diagram illustrating a system on chip according to an embodiment of the disclosure. Differences from Figure 1 the system on chip of
[0089] Referring to Figure 9 , the system on chip can further include a connector 145 connected to the first bus 120.
[0090] The connector 145 can connect the security controller 110 with the first memory 140. The security controller 110 can generate an arbitrary value and declare the value as a security parameter to the first memory 140.
[0091] When the security parameter is stored in the first memory 140 by the security controller 110, the connector 145 can disconnect the security controller 110 from the first memory 140. That is, after the security parameter is injected into the first memory 140, the security controller 110 can not access the first memory 140. Accordingly, since the security controller 110 can not read the security parameter stored in the first memory 140, the security level of the system on chip 300 can be improved.
[0092] According to some other embodiments of the disclosure, the security parameter can be generated by the physically unclonable function 190 or the random number generator 195 and injected into the first memory 140.
[0093] Figure 10 FIG. 1 is a block diagram illustrating a system on chip according to embodiments of the disclosure. Figure 1 FIG. 1 is a block diagram illustrating a system on chip according to embodiments of the disclosure.
[0094] Referring to FIG. 1, a system on chip 300 according to embodiments of the disclosure can include a security module 100 and a normal module 200. Figure 10 The security module 100 of the system on chip 300 can further include a first memory 140.
[0095] The first memory 140 can store a security parameter and provide the security parameter to the encryption / decryption module 150. The first memory 140 can include, for example, an OTP (One Time Programmable) memory.
[0096] The encryption / decryption module 150 can receive the security parameter from the first memory 140 or a second memory 160.
[0097] Figure 11 FIG. 1 is a block diagram illustrating a system on chip according to embodiments of the disclosure. Figure 11 FIG. 1 is a block diagram illustrating a system on chip according to embodiments of the disclosure. Figure 12 FIG. 1 is a block diagram illustrating a system on chip according to embodiments of the disclosure. Figure 1 FIG. 1 is a block diagram illustrating a system on chip according to embodiments of the disclosure.
[0098] Referring to FIG. 1, a system on chip 300 according to embodiments of the disclosure can include a security module 100 and a normal module 200. Figure 11 According to embodiments of the disclosure, the system on chip can include a security module 100 that is powered by receiving power from a first power module 700 and a normal module 200 that is powered by receiving power from a second power module 800.
[0099] The first power module 700 can supply power to the security module 100 at a first time point. The second power module 800 can supply power to the normal module 200 at the first time point or a second time point different from the first time point. Accordingly, the security module 100 can operate by being powered independently of the normal module 200. FIG. 1 is a block diagram illustrating a system on chip according to embodiments of the disclosure.
[0100] Referring to Figure 12 , the shared memory 240 can include a normal region 1000, a trust zone region 1200, and a shared region 1400.
[0101] The host controller 210 can store log data in the shared memory 1400. The log data can include, for example, the number of accesses of the host controller 210 to the external memories 400 and 500, communication data of the host controller 210 with the external memories 400 and 500, a load of the host controller 210, an access record of the module 280, an access record of the electronic device 600, the number of read failures at the time of a read command of the security controller, etc.
[0102] Referring to Figure 11 to Figure 13 , the security controller 110 can access the shared memory 240 to read the log data. The security controller 110 can monitor the log data to determine whether a security attack has occurred in the normal module 200.
[0103] When it is determined that a security attack has occurred in the normal module 200, the security controller 110 can provide a signal SIG indicating the security attack to the host controller 210. Alternatively, for example, the security controller 110 can provide a disable signal DSA to the normal module 200.
[0104] Further, even if the security module 100 is powered on and the normal module 200 is powered off, the security controller 110 can read the log data stored in the shared memory 240. Accordingly, when it is determined that a security attack has occurred in the normal module 200, the security controller 110 can safely activate the normal module 200.
[0105] Figure 14 is a block diagram illustrating a system on chip according to an embodiment of the disclosure. Differences from Figure 11 will be mainly described.
[0106] Referring to Figure 14 , the system on chip can store a security parameter in the first memory 140 or the second memory 160. The encryption / decryption module 150 can receive the security parameter from the first memory 140 or the second memory 160.
[0107] The connector 145 is connected between the security controller 110 and the first memory 140, and can inject the security parameter generated by the security controller 110 into the first memory or the second memory. After storing the security parameter in the first memory 140 or the second memory 160, the connector 145 can disconnect the security controller 110 from the first memory 140.
[0108] According to another embodiment, a security parameter generated by the physical unclonable function 190 or the random number generator 195 can be injected into the first memory 140 and the second memory 160.
[0109] At the end of the detailed description, those skilled in the art will appreciate that many changes and modifications can be made to the preferred embodiments without substantially departing from the principles of the present disclosure. Therefore, the disclosed embodiments are intended to be only generally and descriptive, and not restrictive.
Claims
1. A system-on-chip, comprising: a host controller configured to control a transmission of data between the system-on-chip and an external device; and a security module, comprising: a security controller configured to communicate with the host controller to control the transmission of the data between the system-on-chip and the external device; a first memory configured to store a security parameter; an encryption / decryption module configured to receive the security parameter from the first memory, to encrypt or decrypt the data transmitted between the system-on-chip and the external device based on the security parameter under control of the security controller, and to output secure data and a first message authentication code; and a first memory manager configured to control a transmission of the security parameter from the first memory to the encryption / decryption module for encrypting or decrypting the data transmitted between the system-on-chip and the external device, wherein the encryption / decryption module is further configured to generate a second message authentication code using the security parameter from the first memory, to compare the first message authentication code with the second message authentication code, and to transmit the secure data to the security controller for execution when the first message authentication code is identical to the second message authentication code.
2. The system on chip of claim 1, wherein, The security parameter comprises an encryption key and a timestamp.
3. The system on chip of claim 2, wherein, The security module further comprises: a random number generator, RNG, configured to generate a random number; and a physically unclonable function, PUF, and wherein the security parameter is stored in the first memory based on the random number generated by the random number generator or a signal of the physically unclonable function.
4. The system on chip of claim 2, wherein, The security module further comprises a connector configured to selectively connect the security controller to the first memory, wherein the first memory is connected to the security controller through the connector to store the security parameter, and wherein the connector does not connect the security controller to the first memory when the security controller stores the security parameter in the first memory.
5. The system on chip of claim 1, wherein, The security module further comprises a second memory configured to store the security parameter, and wherein the encryption / decryption module is further configured to receive the security parameter from the first memory or the second memory.
6. The system on chip of claim 5, wherein, The first memory comprises a non-volatile memory, and wherein the second memory comprises a one-time programmable, OTP, memory.
7. The system-on-chip of claim 1, further comprising: a shared non-volatile memory through which the host controller and the security controller communicate, wherein the shared non-volatile memory comprises: a first region accessible to the host controller; and a second region accessible to the host controller and the security controller.
8. The system on chip of claim 7, wherein, The host controller is further configured to store log data in the second region, and wherein the security controller is further configured to access the log data to monitor a security status of the system-on-chip.
9. The system on chip of claim 1, further comprising: an external memory controller configured to provide the data from the encryption / decryption module to an external memory.
10. A system on chip, comprising: a security module configured to receive power from a first power module; a host controller configured to control transmission of data between the system on chip and an external device; and a shared memory configured to store log data under control of the host controller, the host controller and the shared memory configured to receive power from a second power module, wherein the security module comprises: a security controller configured to monitor the log data stored in the shared memory to determine whether a security attack has occurred in the system on chip and to provide a signal indicating the security attack to the host controller based on a determination that the security attack has occurred; a first memory configured to store security parameters, the security parameters comprising an encryption key and a timestamp; and an encryption / decryption module configured to receive the security parameters from the first memory, to encrypt or decrypt data transmitted between the system on chip and the external device based on the security parameters under control of the security controller, and to output secure data and a first message authentication code, wherein the encryption / decryption module is further configured to generate a second message authentication code using the security parameters from the first memory, to compare the first message authentication code to the second message authentication code, and to transmit the secure data to the security controller for execution when the first message authentication code is the same as the second message authentication code, and wherein the shared memory and the first memory are non-volatile memories.
11. The system on chip of claim 10, wherein, the first power module is configured to supply the power provided to the security module at a first point in time, and the second power module is configured to supply the power provided to the host controller and the shared memory at a second point in time different from the first point in time.
12. The system on chip of claim 11, wherein, the first point in time is earlier than the second point in time, and wherein the security controller is further configured to direct the host controller based on a determination that the security attack has occurred.
13. The system on chip of claim 11, wherein, the security controller is further configured to provide a disable signal to the host controller based on a determination that the security attack has occurred.
14. The system on chip of claim 10, wherein, the security module further comprises: a first memory manager configured to control transmission of the security parameters from the first memory to the encryption / decryption module for encryption or decryption of the data transmitted between the system on chip and the external device.
15. The system on chip of claim 14, wherein, the first memory manager comprises: a buffer configured to buffer the data to the first memory under control of the security controller; and a timestamp manager configured to generate the timestamp based on receipt and encryption of the data by the encryption / decryption module.
16. The system on chip of claim 10, further comprising: an external memory comprising: a first region accessible to the host controller; a second region accessible to the host controller and the secure controller; and a third region accessible to the encryption / decryption module, wherein the third region stores encrypted data or encrypted code.
17. The system on chip of claim 16, wherein, The encryption / decryption module is further configured to decrypt the encrypted data or the encrypted code provided from the external memory based on the security parameter.
18. The system on chip of claim 16, wherein, The external memory comprises at least one of a dynamic random access memory (DRAM) or a flash memory.
19. A system on chip, comprising: a secure module configured to receive power from a first power module; a host controller; a shared memory configured to store log data under control of the host controller, the host controller and the shared memory configured to receive power from a second power module; and an interface through which data is transmitted between the system on chip and a plurality of electronic devices, wherein the secure module comprises: a secure controller configured to monitor the log data stored in the shared memory to determine whether a security attack has occurred in the system on chip and to provide a signal indicative of the security attack to the host controller based on a determination that the security attack has occurred, a first memory configured to store a security parameter, a first memory manager configured to control access to the first memory and transmission of the data transmitted between the system on chip and the plurality of electronic devices under control of the secure controller, a second memory configured to store the security parameter, and an encryption / decryption module configured to receive the security parameter from the first memory or the second memory to encrypt the data transmitted between the system on chip and the plurality of electronic devices or to decrypt encrypted data, and to output secure data and a first message authentication code, and wherein the encryption / decryption module is further configured to generate a second message authentication code using the security parameter from the first memory, to compare the first message authentication code with the second message authentication code, and to transmit the secure data to the secure controller for execution when the first message authentication code is identical to the second message authentication code.
20. The system on chip of claim 19, wherein, The shared memory, the first memory, and the second memory are non-volatile memory devices.
Citation Information
Patent Citations
Heat treatment method of high strength bolt
KR1020190094941A
Encryption device, system on chip including the same, and electronic device
CN109829316A
System on chip
US20210042433A1