FUNCTIONAL SECURITY SYSTEMS AND PROCEDURES FOR SECURE ACCESS TO NON-VOIDABLE DATA STORAGE

The system addresses the challenge of achieving a cost-effective and processing-efficient balance in MCU-based systems by dynamically switching between cryptographic modes based on system conditions, enhancing performance and reducing latency and costs.

DE102024130470A1Pending Publication Date: 2025-05-08TEXAS INSTRUMENTS INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
DE102024130470
Authority / Receiving Office
DE · DE
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-31
Filing Date
2024-10-21
Publication Date
2025-05-08

AI Technical Summary

Technical Problem

Existing solutions for embedded systems with microcontroller units (MCUs) fail to achieve a cost-effective and processing-efficient balance between encryption, decryption, and secure access to external non-volatile data storage, particularly due to high throughput and firmware size requirements.

Method used

A system comprising a data storage security controller configured to operate in multiple functional safety modes, a mode selection controller to determine access requirements and incoming answers, and a data storage interface controller to manage access to non-volatile data storage, allowing dynamic switching between cryptographic modes based on system conditions.

Benefits of technology

This approach enhances system performance and efficiency by dynamically adjusting cryptographic operations, reducing design area and costs, and minimizing latency due to bottlenecks, while ensuring secure access to non-volatile data storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

Several examples disclosed here relate to controlling access to non-volatile data storage devices. In one example implementation, a device is created. The device includes a data storage backup controller configured to operate in either a first functional safety mode or a second functional safety mode, a backup mode selector controller coupled to the data storage backup controller, and a data storage interface controller coupled to the data storage backup controller and the backup mode selector controller and configured to connect to a non-volatile data storage device.The backup mode selection controller is configured to determine a number of pending access requests associated with the data storage backup controller, a number of incoming responses from the non-volatile data store to the data storage backup controller, and to select between the first functional safety mode and the second functional safety mode based on the number of pending access requests and / or the number of incoming responses.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] This generally refers to controlling cryptographic processes for secure access to non-volatile data storage devices. BACKGROUND

[0002] Microcontroller units (MCUs) are designed to run software programs and perform functions enabled by the operation of the software programs. To this end, MCUs may include processing cores configured to execute software and memory coupled to the processing cores that stores the software's instructions and data. For example, MCUs may include one or more central processing units (CPUs), each with any number of processing cores, communicating with volatile memory (e.g., random access memory (RAM)) to execute such software programs. If a software program is too large to be executed from RAM, the MCU may additionally use non-volatile memory, such as flash memory, which has a larger capacity to store instructions and data related to the software.MCUs generally run software programs from RAM at greater speed and with reduced latency, but increasing program complexity and size may require the MCU to run from volatile data memory and / or non-volatile data memory to perform the task.

[0003] When non-volatile data storage is used, a processing core can read from or write to a given non-volatile data storage. In many existing solutions, data written to or read from non-volatile data storage can be subjected to encryption or decryption for security and backup purposes. In some of these solutions, such cryptography techniques are required by industry standards (e.g., automotive functional safety standards (e.g., ISO 26262)) to protect systems, devices, and their users from risks due to hazards caused by failing computing systems or malicious attacks by attackers. SUMMARY

[0004] Disclosed here are improvements to control security and assurance with respect to access to non-volatile data storage. In a computing system, a processing core may attempt to access external non-volatile data storage to read data, write data, or execute program instructions directly from the external non-volatile data storage. In such systems, data written to the external non-volatile data storage may first be encrypted, and consequently, data read from the external non-volatile data storage may be decrypted for use by the processing core. A system may use multiple types of encryption and decryption based on how much capacity is available and which elements of the system are more efficient at a given time.

[0005] In one example embodiment, a device is provided. The device includes a data storage backup controller configured to operate in a first functional safety mode or a second functional safety mode, a backup mode selection controller coupled to the data storage backup controller, and a data storage interface controller coupled to the data storage backup controller and the backup mode selection controller and configured to interface with a non-volatile data storage.The backup mode selection controller is configured to determine a number of pending access requests associated with the data storage backup controller, determine a number of incoming responses from the non-volatile data storage to the data storage backup controller, and select between the first functional security mode and the second functional security mode based on the number of pending access requests and / or the number of incoming responses.

[0006] This summary is intended to introduce, in a simplified form, a selection of concepts that are further described below in the detailed description. It should be understood that this summary is not intended to identify key features or essential features of the claimed subject matter, nor should it be used to limit the scope of the claimed subject matter. BRIEF DESCRIPTION OF THE DRAWINGS Fig. 1 illustrates an example system for controlling access to a non-volatile data storage device according to one implementation. Fig. Figure 2 illustrates a series of steps for controlling cryptographic processes and access to data storage devices in one implementation. Fig. 3A and Fig. 3B illustrates example sequence diagrams demonstrating cryptographic control and access between elements of a system, according to one implementation. Fig. 4 illustrates an example block diagram of a system configurable to perform data memory access and cryptographic control in one implementation. Fig. Figure 5 shows an example flowchart for controlling cryptographic processes in an implementation. Fig. Figure 6 shows an example flowchart for performing error testing processes in an implementation. Fig. 7 illustrates a computing device that may be used in accordance with some examples of the present technology.

[0007] The drawings are not necessarily drawn to scale. Throughout the drawings, like reference characters designate corresponding parts throughout the different views. In some examples, components or operations may be separated into different blocks or may be combined into a single block. DETAILED DESCRIPTION

[0008] Improved components, techniques, and systems related to controlling security and safeguards for accessing non-volatile data storage and other types of data storage are discussed here. A processing core may be tasked with executing software to enable the functionality of an application, device, or system. Although the processing core may copy some code and data to internal data storage for execution, it may not be optimal to copy all code and data to internal data storage due to design constraints, cost, and other considerations. Consequently, non-volatile data storage may be contained in a system external to the processing core. In such systems, some code and data may be copied from non-volatile data storage to internal data storage (e.g.,RAM) may be copied at runtime, while other code and data may remain in external non-volatile data storage (e.g., flash data storage) at runtime. The processing core may attempt to access both internal data storage and external data storage during software execution.

[0009] In various examples, for security and backup purposes, a system may encrypt information written to external data storage and decrypt information read from the external data storage. Multiple cryptographic schemes may be used by a system, and multiple cryptographic schemes may be used by a single system. One example cryptography solution in MCUs uses message authentication code (MAC)-based encryption and decryption techniques to provide integrity protection and security support. However, using MAC-based techniques for all incoming and outgoing data to an external flash can incur a significant amount of overhead related to the throughput and firmware size of the non-volatile data storage.Furthermore, some systems may not require integrity protection for all incoming and outgoing data to and from external data storage devices. Another example cryptography solution may use lock-step security techniques to avoid the significant overhead limitations introduced with MAC-based solutions, such as in systems that do not require the integrity protection provided by MAC-based techniques. However, these solutions trade off the overhead with silicon area and design costs. Consequently, previous solutions for embedded solutions using MCUs fail to achieve a cost-effective and processing-efficient balance between encryption, decryption, and secure access to and from external data storage.

[0010] A system disclosed herein includes a security and backup subsystem capable of performing multiple types of cryptography and further capable of switching between functional security mechanisms to ensure that encryption and decryption have been performed correctly. A particular functional security mechanism may be selected based on system conditions, such as whether the backup cores or the external data storage experience more traffic and may therefore be a bottleneck with respect to throughput, responsiveness, processing speed, and processing accuracy. Mode selection circuitry may be configured to identify how many instructions for encryption and decryption are represented in various queues (e.g.,a request queue and / or a command queue) and how many responses are waiting for decryption in various queues (e.g., a response queue) before being fed to one or more processing cores of the system. Based on the numbers in each queue relative to respective thresholds, the mode selection circuitry can enable or disable one or more functional security check operations (e.g., validation processes applied to outputs from a cryptographic process), which can be advantageous for systems that do not require integrity protection. Advantageously, the system can not only enable a different type of functional security check operation for each access request, which can improve system performance and efficiency, but also reduce design space, cost, and throughput losses.

[0011] In one example embodiment, a device is provided. The device includes a data storage backup controller configured to operate in a first functional safety mode or a second functional safety mode, a backup mode selection controller coupled to the data storage backup controller, and a data storage interface controller coupled to the data storage backup controller and the backup mode selection controller and configured to interface with a non-volatile data storage.The security mode selection controller is configured to determine a number of pending access requests associated with the data storage backup controller, determine a number of incoming responses from the non-volatile data storage to the data storage backup controller, and select between the first functional security mode and the second functional security mode based on the number of pending access requests and / or the number of incoming responses.

[0012] In another example, a system is provided that includes one or more processing cores, circuitry coupled to the one or more processing cores, a data storage backup controller configured to apply cryptographic processes, a backup mode selection controller coupled to the data storage backup controller, and a data storage interface controller coupled to the data storage backup controller and the backup mode selection controller and configured to couple to a non-volatile data storage.The security mode selection controller may be configured to determine a number of upcoming access requests associated with the data storage backup controller, determine a number of incoming responses from the non-volatile data storage to the data storage backup controller, and control which cryptographic functional security process is applied to a request and / or a response based on the number of upcoming access requests and / or the number of incoming responses.

[0013] In yet another embodiment, a method is provided. The method includes receiving access requests for data stored in a non-volatile data storage device from one or more processing cores, determining a number of pending access requests of the access requests associated with the non-volatile data storage device, determining a number of incoming responses from the non-volatile data storage device, and selecting which cryptographic functional security process to apply to a request and / or a response based on the number of pending access requests and / or the number of incoming responses.

[0014] Fig. 1 illustrates an example system for controlling access to a non-volatile data storage device according to one implementation. Fig. 1 shows a system 100 including a microcontroller unit (MCU) 105 and a non-volatile data memory 135. The MCU 105 includes processing cores 110-1, 110-2, and 110-n (collectively, processing cores 110), a security module 112, interconnect 115, a data memory 120, peripherals 122, a security and security subsystem 124, and a data memory interface controller 134. The security and security subsystem 124 includes a mode selection controller 126, a functional security controller 128, a request queue 125, a response queue 127, and a data memory security controller 130, which further includes security cores 131 and message authentication code (MAC) cores 132. In various embodiments, the MCU 105 may be configured to execute program instructions stored in the data memory 120 and / or the non-volatile data memory 135 and access control processes such as, for example,the process 200 of . Fig. 2 to be carried out.

[0015] In various examples, system 100 is representative of a processing system that includes various hardware, software, and firmware elements configured to execute program instructions and enable functionality based on the execution thereof. In various examples, the elements of system 100 are located on a chip (e.g., a system on a chip (SoC)). In some examples, some elements may be located off-chip relative to other on-chip elements, such as non-volatile data storage 135. System 100 may be coupled to one or more peripheral devices 122 that may receive data from elements of system 100, such as from executions of application code, to enable the functionality of the one or more peripheral devices.Like the non-volatile data memory 135, one or more of the peripheral devices of the peripherals 122 may be located off-chip, while one or more other peripheral devices may be located on-chip.

[0016] The system 100 includes an MCU 105, which may include various processing devices and data storage devices from which program instructions and data may be read and to which program instructions and data may be written. Specifically, the MCU 105 may include a number of processing cores 110, a security module 112, circuitry 115 coupled to the processing cores 110 and the security module 112, a data storage device coupled to the circuitry 115, a data memory 120, peripherals 122, a security and security subsystem 124 coupled to the circuitry, and a data storage interface controller 134 coupled to the security and security subsystem 124 and to the non-volatile data memory 135.

[0017] Processing cores 110 may be representative of one or more processors, processing cores, or processing circuitry capable of executing software and firmware, such as program instructions (e.g., application code, loadable instructions, read-only data, executed-in-place (XIP) code, and the like). One or more such processing cores may include microcontrollers, digital signal processors (DSPs), general-purpose processing units, central processing units (CPUs), application-specific processors or circuits (e.g., ASICs), and logic devices (e.g., FPGAs), as well as other types of processing devices, combinations, or variations thereof. In various examples, processing cores 110 may attempt to access data storage 120 and / or non-volatile data storage 135 via circuitry 115 to read from or write to a given data storage device.

[0018] The security module 112 may be representative of a processing core, hardware accelerator, or other processing device configured to perform security and security operations on data read from the data storage 120 by one or more of the processing cores 110 or peripherals 122. In various examples, the security module 112 may identify a read request by the processing cores 110 associated with the data storage 120, obtain data associated with the read request, and perform a security and security operation (e.g., encryption, decryption) on the data to verify that the data is not suspicious, malicious, or degraded.

[0019] Data storage 120 may be representative of computer-readable storage media disposed on MCU 105. Data storage 120 may be representative, for example, of random access memory (RAM), tightly coupled memory (TCM), or another type of data storage. Although only one block is illustrated in system 100, data storage 120 may be implemented as multiple data stores functioning in an integrated or separate manner. Data storage 120 may store program instructions and data. The program instructions may include application code, such as instructions that, when executed by processing cores 110, enable functionality. The data may include results and / or other information related to the program instructions, loadable instructions, XIP code, or the like.The processing cores 110 can access the data memory 120 via the interconnect 115 to execute code thereon.

[0020] Some program instructions may be initially stored in non-volatile data storage 135 and copied to data storage 120 for execution by processing cores 110, whereas XIP code stored on non-volatile data storage 135 may be configured to execute directly from non-volatile data storage 135 without first being copied to data storage 120. When executing a set of program instructions, processing cores 110 may attempt to access data storage 120 or the non-volatile data storage device.An access request or attempt or command may refer to a read request, where processing cores 110 read instructions or data from one or more addresses of data memory 120 or non-volatile data memory 135 to perform processing or computations using the instructions or data, or the access attempt may refer to a write request, where processing cores 110 write data to one or more addresses of data memory 120 or non-volatile data memory 135.

[0021] Non-volatile data storage 135 may be representative of non-volatile computer-readable storage media that retains stored information even after power is removed. In some examples, non-volatile data storage 135 may be located externally relative to MCU 105. In some examples, non-volatile data storage 135 may be located internally relative to MCU 105. Examples of non-volatile data storage 135 and 140 may include FeRAM, MRAM, PCM, PRAM, and flash data storage. In one example, non-volatile data storage 135 may include one or more data storage banks included to provide additional capacity for storing instructions and data, such as XIP code, read-only data, secondary boot data, and other loadable instructions.The non-volatile data storage 135 may include a first set of addresses dedicated to storing read-only data and / or secondary boot data, a second set of addresses dedicated to storing data written to the non-volatile data storage 135 by the processing cores 110 via the data storage interface controller 134, and a third set of addresses dedicated to storing program instructions. Other architectures may be considered for the non-volatile data storage 135. In some examples, the non-volatile data storage 135 may include a different type of non-volatile data storage, or combinations or variations thereof.

[0022] The security and assurance subsystem 124 may be representative of a subsystem or module having one or more components configured to provide the processing cores 110 with access to the non-volatile data storage 135 via the data storage interface controller 134 for executing application code thereon, as well as encrypting and decrypting information (e.g., data, program instructions) passed to and from the non-volatile data storage 135 via the data storage interface controller 134. In one example, the security and assurance subsystem 124 may include one or more processors, processing cores, processing circuits, or hardware accelerators (HWAs) that include hardware elements configured to receive access requests (e.g.,read operations, write operations) from the processing cores 110, receiving responses based on the access requests from the non-volatile data storage 135 via the data storage interface controller 134, and performing cryptographic operations on the access requests to the non-volatile data storage 135 and returned access requests or responses thereto from the non-volatile data storage 135. The data storage interface controller 134 may be representative of a device configured to route the access requests to physical address spaces of the non-volatile data storage 135 based on the access requests and to provide access to the non-volatile data storage 135 at the physical addresses.In some examples, the data storage interface controller 134 may comprise a flash interface controller based on the non-volatile data storage 135 comprising a flash data storage. The elements included in the security and backup subsystem 124 may include the mode selection controller 126, the functional security controller 128, the data storage backup controller 130, and the request queue 125 and response queue 127, which may be accessible to each of the aforementioned elements.

[0023] The mode selection controller 126 may be representative of one or more processors, circuits, or devices coupled to both the functional safety controller 128 and the data storage backup controller 130 to control operations thereof. In particular, the mode selection controller 126 may be configured to maintain a current state (e.g.,enabled, disabled) of the functional safety controller 128 and the data storage backup controller 130, identify a number of access requests being processed by the functional safety controller 128 and / or the data storage backup controller 130 in the request queue 125, identify a number of responses being processed by the functional safety controller 128 and / or the data storage backup controller 130 in the response queue 127, and enable or disable operations of the functional safety controller 128 and the data storage backup controller 130 based on system conditions, such as the numbers of access requests and responses in respective queues and the current operations thereof.

[0024] For example, in a first mode (e.g., dual pump mode), the functional safety controller 128 may be configured to perform duplication, filtering, and validation operations to enable functional safety of outgoing requests to the non-volatile data storage 135 and incoming responses based on the outgoing requests from the non-volatile data storage 135. In the first mode, the fuse cores 131 may be configured to perform cryptographic operations on each copy of duplicated requests and responses, and the functional safety controller 128 may be configured to validate results of the cryptographic operations performed by the fuse cores 131. In a second mode (e.g.,In the second mode (MAC mode), the duplication and filtering functionality of the functional security controller 128 can be disabled, and the message authentication code (MAC) cores 132 can be enabled to perform MAC cryptography operations on the requests and responses in addition to the cryptography operations performed by the security cores 131. The functional security controller 128 can thus be configured to validate results from both cryptography operations in the second mode.

[0025] The functional safety controller 128 and the data storage backup controller 130 may be representative of security and security-related circuitry capable of enabling and performing cryptographic operations on access requests from the processing cores 110 and responses based on the access requests from the non-volatile data storage 135. When enabled, the functional safety controller 128 may be configured to duplicate access requests, deliver the duplicated access requests to the request queue 125 and the data storage backup controller 130, and validate each copy of the duplicated access request based on comparing request-related information of the duplicated access requests against each other (e.g., validating that the duplicated requests contain the same information as, for example,addresses, size, protocol-specific parameters, and the like), filter the duplicate access requests received from the data storage backup controller 130 based on the validation, and forward the access requests to the data storage interface controller 134 for access to the non-volatile data storage 135.Furthermore, the functional safety controller 128 may be configured to receive responses based on the access requests from the non-volatile data storage 135 via the data storage interface controller 134, duplicate the responses and add the duplicated responses to the response queue 127, supply the duplicated responses to the data storage backup controller 130 for decryption thereof according to a selected cryptography mode, validate the decryption of each copy of the duplicated response based on the comparison of information related to the response (e.g., validating that the duplicated responses contain the same information as, for example,data, size, and the like), filter the duplicated decrypted responses received from the data storage security controller 130 after decryption and validation, and provide the decrypted responses to the processing cores 110 via interconnect 115. In some examples, in the second mode, the functional security controller 128 may not be disabled, but the duplication and filtering operations may be bypassed, for example, to conserve power and increase throughput.

[0026] To perform encryption and decryption operations, the data storage security controller 130 may include security cores 131 and MAC cores 132. The security cores 131 may be representative of one or more processing cores, circuits, or devices capable of encrypting data to be written to the non-volatile data storage 135 and decrypting data of a response from the non-volatile data storage 135. Likewise, the MAC cores 132 may be representative of one or more processing cores, circuits, or devices capable of performing MAC encryption and MAC decryption when the data storage security controller 130 is enabled to operate in the second mode.In various examples, MAC cores 132 may perform MAC encryption on some or all of the write requests containing information to be written to non-volatile data storage 135, regardless of the selected mode. In various examples, data storage security controller 130 or its cores may be controlled by mode selection controller 126 to enable or disable verification operations applied to outputs from MAC cores 132, such that MAC functional security operations may be enabled or disabled on the access requests and responses.

[0027] To determine whether the first or second mode should be activated to ensure functional reliability of the cryptography, the mode selection controller 126 may be configured to determine a number of pending access requests associated with the data storage backup controller 130 or respective cores thereof in the request queue 125 during a given mode and to determine a number of incoming responses from the non-volatile data storage 135 to the data storage backup controller 130 in the response queue 127. Each incoming response may correspond to one of the pending access requests. Based on the number of pending access requests and incoming responses in the request queue 125, respectively,From the response queue 127, the mode selection controller 126 may determine whether the non-volatile data memory 135 may be slowing down overall operations of the MCU 105 (i.e., is a bottleneck), or whether the data memory backup controller 130 or the functional safety controller 128 may be slowing down operations of the MCU 105 (i.e., is a bottleneck). For example, if the number of pending access requests exceeds a threshold number, the mode selection controller 126 may determine that the non-volatile data memory 135 and the data memory interface controller 134 may not be able to process the access requests and provide responses to the access requests quickly enough, such that the non-volatile data memory 135 and the data memory interface controller 134 may be reducing the processing efficiency, responsiveness, throughput, and the like of the MCU 105.Consequently, the mode selection controller 126 may disable the second mode (MAC mode) and enable the first mode (dual pump mode). Conversely, if the number of incoming responses exceeds a threshold number, the mode selection controller 126 may determine that the data storage backup controller 130 and the functional safety controller 128 may not process (e.g., duplicate, filter) and decrypt the access responses quickly enough, so that the data storage backup controller 130 and the functional safety controller 128 may reduce the processing efficiency, responsiveness, throughput, and the like of the MCU 105. Consequently, the mode selection controller 126 may disable the first mode and enable the second mode of the security and backup subsystem 124. In the first mode, the security and backup subsystem 124 may take longer to perform functional safety operations (e.g.,Duplicating, validating, and filtering access requests and duplicating, decrypting, validating, and filtering corresponding responses) than in the second mode. In this way, by controlling the mode of cryptography and its validation via the functional safety controller 128 and data storage security controller 130, the mode selection controller 126 can dynamically balance the loads of the components of the security and security subsystem 124 and the MCU 105 to increase performance and reduce latency due to bottlenecks.

[0028] In some examples, the mode selection controller 126 may be configured to control which mode should be enabled or disabled based on a selection signal 123 indicating a mode of cryptographic security provided to the mode selection controller 126 by the processing core 110-1. In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 during a boot-up or startup sequence. In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 at a time before or at the beginning of a runtime sequence following boot-up of the MCU 105 and components thereof. In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 based on the execution of program instructions.In some such examples, the processing core 110-1 may provide the selection signal 123 to the mode selection controller 126 after a number of processing cycles.

[0029] In some examples, the mode selection controller 126 may be configured to enable the first mode by default. In some examples, the mode selection controller 126 may be configured to enable the second mode by default. In some examples, the mode selection controller 126 may override the mode based on receiving the selection signal 123. Regardless of the method of implementation, the mode selection controller 126 may be configured to use one mode for a given access request and for a corresponding response to the given access request.

[0030] As a first example, in operation, the processing core 110-1 provides an access request to the security and backup subsystem 124 via the interconnect 115, corresponding to a write request specifying a first set of data to the non-volatile data storage 135. In the first example, the security and backup subsystem 124 may be configured to operate in the first mode. In some examples, based on the access request comprising a write request, the functional safety controller 128 may not be configured to perform duplication operations on the write request, but rather to provide the write request to the backup cores 131 for encryption thereof and forward the encrypted write request to the data storage interface controller 134 for writing the first set of data to the non-volatile data storage 135.In some examples, the functional safety controller 128 may be configured to perform duplication, validation, and filtering operations on the write requests. In some such examples, the functional safety controller 128 may be configured to duplicate the write request and add both write requests to the request queue 125, which in turn may deliver the write request to the backup cores 131 of the data store backup controller 130 based on the first mode being enabled. The backup cores 131 may be configured to encrypt both write requests and deliver the encrypted write requests to the functional safety controller 128 for validation and filtering thereof.The functional safety controller 128 may validate the encryption of the write request, filter out (e.g., discard, do not deliver) one of the write requests based on successful validation, and deliver one of the write requests to the data storage interface controller 134 to write the first set of data to the non-volatile data storage 135.

[0031] According to the first example, the processing core 110-1 may then provide an access request to the security and backup subsystem 124 via interconnect 115, corresponding to a read request specifying the first set of data. Based on being enabled to operate in the first mode, the functional security controller 128 may be configured to receive a response from the non-volatile data storage 135 via the data storage interface controller 134 corresponding to the read request for the first set of data, duplicate the response, and add both responses to the response queue 127. The data storage backup controller 130 may be configured to receive the responses, decrypt both responses via the backup cores 131, and provide the decrypted responses to the functional security controller 128.The functional safety controller 128 may be configured to validate the decryption based on comparing the decrypted responses with each other. In some examples, this may involve comparing the data contained in the responses, the size of the data in each response, and the like. Based on a successful decryption and validation thereof, the functional safety controller 128 may filter out one of the responses and provide the other to the processing core 110-1. Based on an unsuccessful decryption and validation, such as when the information from one response does not match the information in the other response, the functional safety controller 128 may provide an indication of this to the processing core 110-1.

[0032] In a second example, processing core 110-1 provides an access request to security and backup subsystem 124 via interconnect 115, corresponding to a write request specifying a second set of data to non-volatile data storage 135. In this second example, security and backup subsystem 124 may be configured to operate in the second mode. Based on the second mode, functional security controller 128 may be configured to add the write request to request queue 125 without duplicating it. Data storage backup controller 130 may receive the write request from request queue 125 and perform encryption thereof via backup cores 131.Based on the second mode, the data storage backup controller 130 may be further configured to perform MAC encryption on the write request via the MAC cores 132. In this way, the backup cores 131 may encrypt the second set of data, and the MAC cores 132 may add MAC information to the encrypted second set of data. In some examples, the encrypted request may include 32 bytes of data and the MAC information may include 16 bytes of data; thus, the encrypted request may include a total of 48 bytes of data. The data storage backup controller 130 may provide the encrypted request to the functional security controller 128 for encryption validation.The functional safety controller 128 may provide the encrypted request to the data storage interface controller 134 to write the second set of data to the non-volatile data storage 135.

[0033] According to the second example, the processing core 110-1 may then provide an access request to the safety and security subsystem 124 via interconnect 115, corresponding to a read request specifying the second set of data. Based on being enabled to operate in the second mode, the functional safety controller 128 may be configured to receive a response from the non-volatile data storage 135 via the data storage interface controller 134, corresponding to the read request for the second set of data and the response to the response queue 127, without duplication thereof.The data storage backup controller 130 may be configured to receive the response, decrypt the response via the backup cores 131, perform MAC validation of the MAC information of the decrypted response via the MAC cores 132, and provide the decrypted response to the functional safety controller 128. The functional safety controller 128 may be configured to validate the decryption based on the comparison of the decrypted data with the second set of data and to validate the MAC information (e.g., a MAC value) based on the comparison of the MAC information received from the non-volatile data storage 135 with the MAC information added to the outgoing request to the non-volatile data storage 135. Based on successful decryption and validation thereof, the functional safety controller 128 may provide the second set of data to the processing core 110-1.Based on unsuccessful decryption and validation, such as when the incoming MAC information does not match the outgoing MAC information, the functional safety controller 128 may provide an indication thereof to the processing core 110-1.

[0034] Between the time processing core 110-1 delivers the read request and the corresponding write request, both related to the first set of data as in the first example, security and backup subsystem 124 may perform cryptographic processes on other access requests related to other data (e.g., the access requests related to the second set of data as in the second example). Before processing these other access requests, mode selection controller 126 may be configured to determine a number of pending access requests in request queue 125, determine a number of pending responses in response queue 127, and control the mode of functional security controller 128 and data storage backup controller 130 based on the determined numbers relative to respective thresholds.Consequently, the mode of the security and backup subsystem 124 may change one or more times to process the other access requests that occur between the read and write requests of the first example. Other combinations or variations of access requests, responses, and mode switching to enable various cryptographic operations may be considered.

[0035] In various examples, regardless of the operating mode, the data storage backup controller 130 may be configured to encrypt data to be written to the non-volatile data storage 135 using both backup cores 131 and MAC cores 132 such that each set of encrypted data written to the non-volatile data storage 135 includes MAC information associated with the encrypted data.

[0036] In various examples, non-volatile data storage 135 may further provide error check indications to MCU 105 via data storage interface controller 134, which may be provided to processing cores 110 via interconnect 115. Upon receiving an indication, such as an interrupt indication, processing core 110-1 may provide a select signal 123 to mode selection controller 126 to enable or disable a mode of functional safety controller 128 and data storage backup controller 130.

[0037] These examples discuss only a few situations and some types of access requests; however, combinations and variations of requests for accessing different types of data storage and using different types of encryption and decryption techniques can be considered. Regardless of the type of data storage, the addresses being attempted to access, the type of cryptography, and the like, the mode selection controller 126 can switch between two or more types of cryptographic functional security methods to ensure that requests and responses thereto are performed in an order that at least increases the processing efficiency and throughput of the processing cores 110 and the MCU 105, while also reducing latency caused by bottlenecks.

[0038] Fig. Figure 2 illustrates a series of steps for controlling cryptographic processes and access to data storage devices in an implementation. Fig. 2 shows a process 200 that accesses elements of Fig. 1. The process 200 may be performed by one or more components of a processing system such as the MCU 105 of Fig. 1. Consequently, the process 200 may be implemented in hardware, firmware, and / or software, or combinations or variations thereof.

[0039] In operation 205, the security and safeguard subsystem 124 may be configured to receive access requests for data stored in the non-volatile data storage 135 from one or more of the processing cores 110. An access request may refer to a read request, where the processing cores 110 read instructions or data from one or more addresses of the data storage 120 or non-volatile data storage 135 to perform processing or computations using the instructions or data, or the access attempt may refer to a write request, where the processing cores 110 write data to one or more addresses of the data storage 120 or non-volatile data storage 135. The security and safeguard subsystem 124 may include various components, such as:the mode selection controller 126, the functional safety controller 128, and the data storage backup controller 130, which are coupled to receive the access requests from the one or more processing cores, apply cryptographic techniques to the access requests, and provide the access requests to the data storage interface controller 134 for access to the non-volatile data storage 135. In particular, the functional safety controller 128 may be coupled to receive the access requests from one or more of the processing cores 110 via the interconnect 115.

[0040] Next, in operation 210, the security and backup subsystem 124 or the mode selection controller 126 thereof may be configured to determine a number of pending access requests associated with the non-volatile data storage 135 in the request queue 125. An pending access request may refer to an access request in an access request queue waiting to be encrypted or decrypted by the data storage backup controller 130. In operation 215, the security and backup subsystem 124 or the mode selection controller 126 thereof may be configured to determine a number of incoming responses from the non-volatile data storage 135 in the response queue 127.An incoming response may refer to a response provided to the security and backup subsystem 124 from the non-volatile data storage 135 via the data storage interface controller 134 based on an access request. In particular, the incoming response may include data or program instructions requested in an access request following access of the non-volatile data storage 135 via the data storage interface controller 134. Each incoming response may be associated with a given access request. Each incoming response may be indicated in the response queue 127. Thus, the mode selection controller 126 may identify the number of incoming responses in the response queue 127 during this step.

[0041] In various examples, the storage backup controller 130 may perform encryption and decryption operations on the contents of upcoming access requests in the request queue 125 and upcoming responses in the response queue 127 on a first-in, first-out (FIFO) basis. The storage backup controller 130 may include backup cores 131 and MAC cores 132 that may perform cryptographic operations on the requests and responses thereto. For example, the backup cores 131 may be configured to perform encryption on access requests and decryption on corresponding responses in both a first mode and a second mode configured by the mode selection controller 126.The MAC cores 132 may be configured to perform MAC encryption on access requests encrypted by the backup cores 131 and MAC decryption on responses decrypted by the backup cores 131 in the second mode configured by the mode selection controller 126. In some examples, the MAC cores 132 may also perform MAC encryption on access requests in the first mode. In some examples, the functional security controller 128 may perform various functional security validation operations on the encrypted and / or decrypted requests and responses based on a selected mode.

[0042] In operation 220, the security and assurance subsystem 124 or the mode selection controller 126 thereof may be configured to select which cryptographic functional security process to apply to validate cryptographic operations applied to the upcoming access requests and / or the corresponding incoming responses based on the number of upcoming access requests in the request queue 125 and / or the number of incoming responses in the response queue 127. In various examples, this may include determining whether the non-volatile data storage 135 may slow down the overall operations of the MCU 105 (i.e., is a bottleneck) or whether the data storage assurance controller 130 or the functional security controller 128 may slow down operations of the MCU 105 (i.e.,a bottleneck) based on the number of pending access requests and incoming responses. For example, the mode selection controller 126 may compare the numbers to respective threshold numbers. If the number of pending access requests exceeds a threshold number, the mode selection controller 126 may determine that the non-volatile data memory 135 and the data memory interface controller 134 may not process the access requests and provide responses to the access requests quickly enough, such that the non-volatile data memory 135 and the data memory interface controller 134 may reduce the processing efficiency, responsiveness, throughput, and the like of the MCU 105.Consequently, the mode selection controller 126 may disable operations in the second mode (cryptographic MAC functional security) and enable operations in the first mode (cryptographic dual pump functional security). Conversely, if the number of incoming responses exceeds a threshold number, the mode selection controller 126 may determine that the memory backup controller 130 and the functional security controller 128 may not be able to process (e.g., duplicate, filter) and decrypt the responses quickly enough, so that the memory backup controller 130 and the functional security controller 128 may reduce the processing efficiency, responsiveness, throughput, and the like of the MCU 105. Consequently, the mode selection controller 126 may disable operations of the functional security controller 128 and the memory backup controller 130 in the first mode and enable operations thereof in the second mode.

[0043] In the first mode, duplication and filtering functional security operations of the functional security controller 128 can be enabled. In this manner, the security cores 131 of the data storage security controller 130 can be used to encrypt and / or decrypt multiple access requests and responses, respectively, and the functional security controller 128 can validate the encryption and / or decryption thereof based on comparing the results of the cryptographic operations performed on the multiple requests and responses. In the second mode, duplication and filtering functional security operations of the functional security controller 128 can be deactivated.As such, the security cores 131 can be used to encrypt and / or decrypt individual access requests and responses, and the MAC cores 132 can be used to add MAC information to the encrypted requests and validate MAC information of the decrypted responses. In the first mode, the security and assurance subsystem 124 may take longer to perform cryptographic functional security operations on access requests and corresponding responses based on performing double-pumping techniques than in the second mode, since twice the number of requests and responses can be encrypted or decrypted, respectively.In this manner, by controlling the mode of cryptography via the functional safety controller 128 and data storage backup controller 130, the mode selection controller 126 can dynamically balance the loads of the components of the security and backup subsystem 124 and the MCU 105 to increase performance and reduce latency due to bottlenecks.

[0044] Fig. 3A and Fig. 3B illustrates example sequence diagrams demonstrating cryptographic control and access between elements of a system, according to one implementation. Fig. 3A shows a sequence 301 and Fig. 3B shows a sequence 302, both of which refer to elements of the system 100.

[0045] Sequences 301 and 302 may include operations performed by elements of system 100 with respect to read requests from one or more of processing cores 110, such as processing core 110-1. In some sequences with respect to write requests, elements of system 100 may perform cryptographic functional security operations to encrypt data written to non-volatile data storage and validate the encryption thereof based on a selected mode enabled by mode selection controller 126.

[0046] In sequence 301, the processing core 110-1 supplies an access request to the security and assurance subsystem 124 or its functional security controller 128 via interconnect 115, corresponding to a read request indicating a first set of data stored in the non-volatile data storage 135. Before the read request is performed by the data storage interface controller 134, the mode selection controller 126 of the security and assurance subsystem 124 may be configured to determine a number of pending access requests associated with the non-volatile data storage 135 in the request queue 125 and a number of incoming responses from the non-volatile data storage 135 in the response queue 127 to determine a cryptographic functional security mode in which components of the security and assurance subsystem are to be activated.Based on the request queue 125 and response queue 127, the mode selection controller 126 may be configured to enable a first mode of cryptographic operations (cryptographic dual pump functional security) and provide an indication of the first mode to the functional security controller 128 and the data storage security controller 130.

[0047] Based on the first mode indication, the functional safety controller 128 may be configured to duplicate the read request and feed the duplicated read requests to the request queue 125. The data storage backup controller 130 may be configured to receive the read requests from the request queue 125. The data storage backup controller 130 may be configured to identify the first mode indication. The functional safety controller 128 may then be configured to validate the duplication of the read requests based on comparing information from each of the read requests.If the functional safety controller 128 confirms that the information of each read request matches, the functional safety controller 128 may filter out one of the read requests and forward the read request to the data storage interface controller 134 for accessing the non-volatile data storage 135 based on the read request.

[0048] Next, the functional safety controller 128 may be configured to receive a response from the non-volatile data storage 135 via the data storage interface controller 134 with the first set of encrypted data. The functional safety controller 128 may duplicate the response and add the responses to the response queue 127. The backup cores 131 of the data storage backup controller 130 may be configured to receive the duplicated responses from the response queue 127. The backup cores 131 may decrypt both responses based on the first mode being enabled and provide the sets of decrypted data to the functional safety controller 128. The functional safety controller 128 may then validate whether the decryption of the responses was successful. In various examples, this may involve comparing the information of each decrypted response, such asthe sizes of the responses, the data of the responses, and the like. Based on a successful decryption, the functional safety controller 128 may filter the duplicated, decrypted responses and provide the first set of decrypted data to the processing core 110-1 via interconnect 115. Based on an unsuccessful decryption, the functional safety controller 128 may be configured to output an indication thereof to the processing cores 110.

[0049] In sequence 302, the processing core 110-1 provides an access request to the security and assurance subsystem 124 or its functional security controller 128 via interconnect 115, corresponding to a read request specifying a second set of data stored in the non-volatile data storage 135. Before the read request is performed by the data storage interface controller 134, the mode selection controller 126 of the security and assurance subsystem 124 may be configured to determine a number of pending access requests associated with the non-volatile data storage 135 in the request queue 125 and a number of incoming responses from the non-volatile data storage 135 in the response queue 127 to determine a cryptographic functional security mode in which components of the security and assurance subsystem are to be activated.Based on the request queue 125 and response queue 127, the mode selection controller 126 may be configured to enable a second mode of cryptographic operations (cryptographic MAC functional security) and provide an indication of the second mode to the functional security controller 128 and the data storage backup controller 130.

[0050] In the second mode, duplication and filtering operations of the functional safety controller 128 may be disabled. Rather, the functional safety controller 128 may be configured to add the read request to the request queue 125 without duplicating the request. The data storage backup controller 130 may receive the read request from the request queue 125 and forward the read request to the data storage interface controller 134 for accessing the non-volatile data storage 135 based on the read request.

[0051] Next, the functional safety controller 128 may be configured to receive a response from the non-volatile data storage 135 via the data storage interface controller 134 with the second set of encrypted data. The functional safety controller 128 may add the response to the response queue 127 without duplicating the response. The data storage backup controller 130 may be configured to receive the response from the response queue 127. The backup cores of the data storage backup controller 130 may be configured to decrypt the response and provide the decrypted response to the MAC cores 132 of the data storage backup controller 130 based on the second mode being enabled.The MAC cores 132 may validate the MAC information of the decrypted response based on the comparison of the MAC information received from the non-volatile data storage 135 with the MAC information used to encrypt the second set of data. Based on a successful validation of the MAC information and the response information, the data storage backup controller 130 may be configured to provide the response to the processing core 110-1 via the interconnect 115. Based on an unsuccessful validation, such as when the MAC information of the response does not match the MAC information used to encrypt the second set of data, the data storage backup controller 130 may output an indication thereof to the processing cores 110.

[0052] Fig. 4 illustrates an example block diagram of a system configurable to perform data storage access and cryptography control in one implementation. Fig. 4 shows a system 400 that includes and references elements of system 100, such as processing core 110-1, mode selection controller 126, data storage backup controller 130, data storage interface controller 134, and non-volatile data storage 135. System 400 also includes an instruction duplicator 405, a response error injection 406, a response checker 407, a request queue 125, an instruction filter 411, an instruction error injection 412, an instruction checker 413, an inline backup interface controller 415, a response duplicator 416, a response queue 127, a response filter 418, an error interface 419, and a status register 421.In various examples, the command duplicator 405, the command filter 411, the command fault injection 412, the command checker 413, the inline fuse interface controller 415, the response duplicator 416, the response filter 418, and the fault interface 419 may be included in a functional safety element of a system, such as the functional safety controller 128 of the system 100.

[0053] In various examples, system 400 is representative of a processing system including various hardware, software, and firmware elements configured to execute program instructions and enable functionality based on the execution thereof. In various examples, the elements of system 400 are located on a chip (i.e., a system-on-chip (SoC)). In some examples, some elements may be located off-chip relative to other elements on-chip, such as non-volatile data storage 135.

[0054] The processing core 110-1 of the system 400 may be representative of a processor, a processing core, or processing circuitry capable of executing software and firmware, such as program instructions (e.g., application code, loadable instructions, read-only data, executed-in-place (XIP) code, and the like). Examples of the processing core 110-1 may include a microcontroller, digital signal processor (DSP), a general-purpose processing unit, a central processing unit (CPU), an application-specific processor or application-specific circuit (e.g., ASIC), and one or more logic devices (e.g., FPGAs), as well as other types of processing devices, combinations, or variations thereof. In various examples, the processing cores 110-1 may attempt to access the non-volatile data storage 135 to read from or write to the non-volatile data storage 135.The non-volatile data memory 135, a non-volatile data memory, may include one or more flash data memory banks included to provide additional capacity for storing instructions and data, such as XIP code, read-only data, secondary boot data, and other loadable instructions accessible to the processing core 110-1 via the data memory interface controller 134 and various security and safeguard components.

[0055] The mode selection controller 126, the data storage backup controller 130, the command duplicator 405, the response error injection 406, the response checker 407, the request queue 125, the command filter 411, the command error injection 412, the command checker 413, the inline backup interface controller 415, the response duplicator 416, the response queue 127, the response filter 418, the error interface 419, and the status register 421 may collectively be referred to as safety and security components of the system 400. These components may be representative of a subsystem (e.g., security and backup subsystem 124) configured to provide processing core 110-1 with access to non-volatile data storage 135 via data storage interface controller 134 for executing application code thereon and encrypting and decrypting information (e.g.,Data, program instructions) passed to and from the non-volatile data storage 135 via the data storage interface controller 134. In one example, these components may be coupled to receive access requests (e.g., reads, writes) from the processing core 110-1, receive responses based on the access requests from the non-volatile data storage 135 via the data storage interface controller 134, and perform cryptographic operations and cryptographic functional security operations on access requests to the non-volatile data storage 135 and returned access requests (responses) from the non-volatile data storage 135.The data storage interface controller 134 may be configured to direct the access requests to physical address spaces of the non-volatile data storage 135 based on the access requests and provide access to the non-volatile data storage 135 at the physical addresses.

[0056] The mode selection controller 126 may be representative of one or more processors, circuits, or devices coupled to the instruction duplicator 405, the instruction filter 411, and the data storage backup controller 130 to control operations thereof. The mode selection controller 126 may also be coupled to the request queue 125 and the response queue 127. In particular, the mode selection controller 126 may be configured in operation to determine a current state (e.g., enabled, disabled) (i.e., mode) of the dual pump function security circuitry (e.g.,Command duplicator 405, response duplicator 416) and data storage backup controller 130, identify a number of access requests in request queue 125, identify a number of responses in response queue 127, and enable or disable operations of the dual pump function security circuitry and data storage backup controller 130 based on the numbers and the current operations thereof. In various examples, mode selection controller 126 may identify the current operational state of the components based on an indication of status register 421.The status register 421 may, for example, comprise a memory mapped register (MMR) that includes indications of states of the dual pump function security circuitry and the memory backup controller 130 at given times and with respect to a given access request and corresponding response.

[0057] When enabled to operate in a first mode based on control by the mode selection controller 126, the command duplicator 405, the command filter 411, the response duplicator 416, the response filter 418, and the data storage backup controller 130 may be configured to operate to duplicate, encrypt, or decrypt access requests and responses using a first method of cryptographic functional security (dual pump functional security) (i.e., via a first set of backup cores of the data storage backup controller 130 (e.g., backup cores 131)), validate, and filter.When enabled to operate in a second mode, duplication and filtering functions of command duplicator 405, command filter 411, response duplicator 416, and response filter 418 may be disabled, and data storage backup controller 130 may utilize the first set of backup cores and a second set of backup cores (e.g., MAC cores 132) capable of performing message authentication code (MAC) encryption and decryption to encrypt and decrypt access requests and corresponding responses, respectively.

[0058] To determine whether cryptographic functional security should be enabled using the first mode or the second mode, the mode selection controller 126 may be configured to determine a number of pending access requests associated with the data storage backup controller 130 or respective cores thereof in the request queue 125 during a given mode and to determine a number of incoming responses from the non-volatile data storage 135 to the data storage backup controller 130 in the response queue 127. Each incoming response may correspond to one of the pending access requests. Based on the number of pending access requests and incoming responses in respective queues, the mode selection controller 126 may determine whether the non-volatile data storage 135 may slow down entire operations of the system 400 (i.e.,a bottleneck) or whether the data storage backup controller 130 or the dual pump function security circuitry may slow down operations of the system 400 (ie, is a bottleneck).

[0059] For example, if the number of pending access requests exceeds a threshold number, the mode selection controller 126 may determine that the non-volatile data memory 135 and the data memory interface controller 134 may not process the access requests and provide responses to the access requests quickly enough, so that the non-volatile data memory 135 and the data memory interface controller 134 may reduce the processing efficiency, responsiveness, throughput, and the like of the MCU 105. Consequently, the mode selection controller 126 may disable the second mode (MAC functional safety) and enable the first mode (dual pump functional safety).Conversely, if the number of incoming responses exceeds a threshold number, the mode selection controller 126 may determine that the memory backup controller 130, the command duplicator 405, the command filter 411, the response duplicator 416, and the response filter 418 may not process (e.g., duplicate, validate, filter) and decrypt the access requests and responses quickly enough, so that the memory backup controller 130 and the dual pump circuitry may reduce the processing efficiency, responsiveness, throughput, and the like of the MCU 105. Consequently, the mode selection controller 126 may disable the first mode and enable the second mode and update the status register 421 accordingly.

[0060] As a first example, in operation, processing core 110-1 provides an access request to the security and assurance components of system 400 for accessing non-volatile data storage 135 based on the access request and the decryption of information specified in the access request. In particular, processing core 110-1 may provide the access request to instruction duplicator 405. The access request may correspond to a read request specifying a first set of data to be read from non-volatile data storage 135. In this first example, the security and assurance components of system 400 may be configured to operate in a first mode (e.g., dual pump function security mode). In some examples, mode selection controller 126 may control some of the components of system 400 to operate in the first mode.In some examples, the processing core 110-1 may instruct the mode selection controller 126 to control the components to operate in the first mode.

[0061] Based on being enabled to operate in the first mode, the command duplicator 405 may be configured to duplicate the read request and add the read requests to the request queue 125. The data storage backup controller 130 may receive the read requests from the request queue 125, record an indication of the first mode corresponding to the read requests, and provide the read requests to the command verifier 413 to validate the duplication performed by the command duplicator 405. The command verifier 413 may be configured to perform a comparison between the two read requests to validate the duplication. In some examples, the command verifier 413 may be configured to store information such as the addresses of the read requests, the number of bytes of the read requests (e.g.,The read request is compared to the read request's size (e.g., size) and protocol-specific information. Based on an unsuccessful check, the command verifier 413 may issue an indication thereof (e.g., an interrupt signal) to the processing core 110-1 indicating a failure in the dual pump function safety operation. Based on a successful check, the command verifier 413 may pass the read requests to the command filter 411 for filtering one of the read requests (e.g., discarding).

[0062] The command filter 411 may filter the read requests so that the command filter 411 provides a read request to the inline backup interface controller 415. Next, the inline backup interface controller 415 may perform additional backup operations on the read request and provide the read request to the data storage interface controller 134. The data storage interface controller 134 may then access the non-volatile data storage 135 to obtain the first set of data specified by the read request at a set of addresses of the non-volatile data storage 135 based on the read request.

[0063] Upon receiving the first set of data, the data storage interface controller 134 may provide a response from the non-volatile data storage 135 containing the first set of data to the inline backup interface controller 415. The inline backup interface controller 415 may perform backup operations on the response (e.g., malware detection) and provide the response to the response duplicator 416. Based on operation in the first mode, the response duplicator 416 may duplicate the response and add the responses to the response queue 127. The data storage backup controller 130 may receive the responses from the response queue 127. The data storage backup controller 130 may then use the first set of backup cores (e.g., backup cores 131) to decrypt each copy of the duplicated responses.After decryption, the data storage backup controller 130 may provide the decrypted responses to the response verifier 408 to validate the decryption. The response verifier 408 may be configured to validate the decryption based on performing a comparison between the two decrypted responses to determine whether the decrypted information (e.g., the size of the response, the data, or the text of the response) is the same between the responses. Based on an unsuccessful verification, the response verifier 408 may be configured to output an indication thereof to the processing core 110-1. Based on a successful verification, the response verifier 408 may provide the decrypted responses to the response filter 418 for filtering.

[0064] Response filter 418 may filter the decrypted responses so that response filter 418 provides an encrypted read request to error interface 419. Error interface 419 may determine whether an error occurred during decryption or the response, and if not, provide the response with the first set of decrypted data to processing core 110-1. If error interface 419 detects an error, error interface 419 may provide an indication of the error to processing core 110-1 if it is not already provided by another element of system 400.

[0065] As a second example, in operation, processing core 110-1 provides an access request to the security and assurance components of system 400 for accessing non-volatile data storage 135 based on the access request and the decryption of information specified in the access request. In particular, processing core 110-1 may provide the access request to instruction duplicator 405. The access request may correspond to a read request specifying a second set of data to be read from non-volatile data storage 135. In this second example, the security and assurance components of system 400 may be configured to operate in a second mode (e.g., MAC functional security mode). In some examples, mode selection controller 126 may control the components to operate in the second mode.In some examples, the processing core 110-1 may instruct the mode selection controller 126 to control the components to operate in the second mode.

[0066] Based on being enabled to operate in the second mode, the command duplicator 405 may be configured to add the read request to the request queue 125 without duplicating the read request. The data storage backup controller 130 may receive the read request from the request queue 125 and pass the read request to the command verifier 413. The command verifier 413 may pass the read request to the command filter 411, which, given the lack of duplication of the read request by the command duplicator 405 based on the second mode operation, may not perform any filtering. The command filter 411 may pass the read request to the inline backup interface controller 415. Next, the inline backup interface controller 415 may perform additional backup operations on the read request and forward the read request to the data storage interface controller 134.The data storage interface controller 134 may then access the non-volatile data storage 135 to obtain the second set of data specified by the read request at a set of addresses of the non-volatile data storage 135 based on the read request.

[0067] Upon receiving the second set of data, the data storage interface controller 134 may provide a response from the non-volatile data storage 135 containing the second set of data to the inline backup interface controller 415. The inline backup interface controller 415 may perform backup operations on the response (e.g., malware detection) and provide the response to the response duplicator 416. Based on operation in the second mode, the response duplicator 416 may add the response to the response queue 127 without duplication. The data storage backup controller 130 may receive the response from the response queue 127. The data storage backup controller 130 may use the first set of backup cores (e.g., backup cores 131) and the second set of backup cores (e.g., MAC cores 132) to decrypt the response and perform functional security validation thereof.In particular, the first set of backup cores may be configured to decrypt the second set of encrypted data of the response and supply the decrypted data to the second set of backup cores. The second set of backup cores may be configured to validate the MAC information associated with the decrypted data based on a comparison of the MAC information received in the response with the MAC information used to encrypt the second set of data.

[0068] Based on unsuccessful validation of the MAC information or other information of the response (e.g., the size of the response, the data, or the body of the response), the data storage backup controller 130 may be configured to output an indication thereof to the processing core 110-1. Based on successful validation of both the MAC information and the other information of the response, the data storage backup controller 130 may output the decrypted data to the error interface 419 and bypass other elements of the system 400 based on being enabled to operate in the second mode (e.g., response verifier 408). In some examples, the data storage backup controller 130 may still provide the decrypted response to the response verifier 408 despite being enabled to operate in the second mode.However, based on being enabled to operate in the second mode, response verifier 408 may provide the decrypted responses to response filter 418, which may not provide filtering due to the lack of duplication of the response by response duplicator 416. Response filter 418 may then provide the encrypted response to error interface 419. Error interface 419 may determine whether an error occurred during decryption or in the response, and if not, provide the response with the second set of decrypted data to processing core 110-1. If error interface 419 detects an error, error interface 419 may provide an indication thereof to processing core 110-1.

[0069] Between the time processing core 110-1 submits the read request as in the first example and the read request as in the second example, the security and backup components may perform cryptographic processes on other access requests relating to other data. Before processing these other access requests, mode selection controller 126 may be configured to determine a number of pending access requests in request queue 125, determine a number of pending responses in response queue 127, and control the mode of command duplicator 405, command filter 411, response duplicator 416, response filter 418, and data storage backup controller 130 based on the determined numbers relative to respective thresholds.Consequently, the mode of the security and assurance components may change one or more times to process the other access requests that occur between the access requests of the above examples. For example, the processing core 110-1 may serve the first read request, specifying the first set of data, at a first time and the second read request, specifying the second set of data, at a second time later than the first time. Consequently, the mode selection controller 126 may switch modes between successive access requests based on this example. Other combinations or variations of access requests, responses, and mode switching to enable different cryptographic operations may be considered.

[0070] In various examples, non-volatile data storage 135 may further provide error check indications to data storage backup controller 130 via data storage interface controller 134, which may be provided to processing core 110-1 via interconnect 115. An example indication may include a MAC error, which may indicate an error in encrypting or decrypting an access request when components of system 400 are operating in the second mode (MAC mode). Upon determining a MAC error, data storage interface controller 134 may provide an indication to inline backup interface controller 415, which may provide the MAC error indication to data storage backup controller 130 and / or processing core 110-1. Based on receiving a MAC error indication, processing core 110-1 may be configured to retry the access request or interrupt operations.

[0071] Fig. Figure 5 shows an example flowchart for controlling cryptographic processes in an implementation. Fig. 5 includes a method 500 that is based on elements of Fig. 1 and Fig. 4. The method 500 may be performed by one or more components of a processing system such as the MCU 105 of Fig. 1 and the System 400 from Fig. 4. Consequently, the method 500 may be implemented in hardware, firmware, and / or software, or combinations or variations thereof.

[0072] In operation 505, the mode selection controller 126 may determine whether adaptive switching is enabled. Adaptive switching may refer to a mode of the mode selection controller 126 that, when enabled, enables the mode selection controller 126 to control cryptographic modes of security and assurance components of a system (e.g., functional safety controller 128, data storage assurance controller 130). To enable adaptive switching, one of the processing cores 110, such as processing core 110-1, may provide an enable signal (e.g., select signal 123) to the mode selection controller 126. In some examples, the enable signal may also include an indication of which cryptographic mode that the mode selection controller 126 should enable.

[0073] Based on the adaptive switching of the mode selection controller 126 being disabled, the mode selection controller 126 may, in operation 510, enable a cryptography mode (e.g., MAC cryptography, double pump cryptography) based on an indication provided by the processing core 110-1 via the select signal 123. In some examples, the mode indicated and enabled by the select signal 123 may be determined based on the processing core 110-1 executing program instructions (i.e., enabled by software). In some examples, a value of the select signal 123 may be user-selected or predetermined.

[0074] Based on the adaptive switching of the mode selection controller 126 being enabled, the mode selection controller 126 may be configured in operation 515 to determine a number of pending access requests associated with the non-volatile data storage 135. An pending access request may refer to an access request in an access request queue waiting to be encrypted by the data storage backup controller 130. The data storage backup controller 130 may compare the number of pending access requests to a threshold number. In some examples, the threshold number may be a predetermined number based on a capacity of an access request queue (e.g., the request queue 125).In response to determining that the number of pending access requests exceeds the threshold number, in operation 525, the mode selection controller 126 may control the security and assurance components to operate in a dual-pump function security mode to apply cryptographic dual-pump function security operations to access requests and corresponding responses. In response to determining that the number of pending access requests does not exceed the threshold number, in operation 530, the mode selection controller 126 may control the security and assurance components to operate in a MAC function security mode to apply MAC function security operations to the access requests and corresponding responses.

[0075] Further, based on the adaptive switching of the mode selection controller 126 being enabled, the mode selection controller 126 may be configured in operation 520 to determine a number of incoming, upcoming responses associated with the non-volatile data storage 135. A response may refer to information returned from the non-volatile data storage 135 to the data storage interface controller 134 based on the access request. Each response may be provided based on an access request and may thus be associated with a specific access request. The data storage backup controller 130 may compare the number of incoming responses to a threshold number. In some examples, the threshold number may be a predetermined number based on a capacity of a response queue (e.g., the response queue 127).In some examples, this threshold number may be the same as or different from the threshold number associated with the access request queue. In response to determining that the number of incoming responses exceeds the threshold number, the mode selection controller 126 may, in operation 530, control the security and backup components to operate in MAC functional security mode. In response to determining that the number of pending access requests exceeds the threshold number, the mode selection controller 126 may, in operation 525, control the security and backup components to operate in dual pump functional security mode.

[0076] Fig. Figure 6 shows an example flowchart for controlling cryptographic processes in an implementation. Fig. 6 includes a method 600 that is based on elements of Fig. 1 and Fig. 4. The method 600 may be performed by one or more components of a processing system such as the MCU 105 of Fig. 1 and the System 400 from Fig. 4. Consequently, the method 600 may be implemented in hardware, firmware, and / or software, or combinations or variations thereof.

[0077] In various examples, method 600 may include a series of steps related to testing the functionality of components of a system. As such, the steps of method 600 may not relate to or be used during runtime operations of a system. However, in some examples, the testing steps may be used intermittently during runtime operations to ensure correct, appropriate operation of safety and security components of a system (e.g., safety and security subsystem 124 and components thereof).

[0078] In operation 605, processing core 110-1 begins a test of the security and safety components of a system. In this step, processing core 110-1 may supply an access request to the security and safety components and may further enable mode selection controller 126 to control the security and safety components to operate in dual-pump security mode. In this mode, command duplicator 405 may duplicate the access request and supply the duplicated requests to command verifier 413, among other components.

[0079] In operation 610, processing core 110-1 uses instruction error injection 412 to randomly degrade data and feed the degraded data to instruction verifier 413. During this step, instruction verifier 413 may be configured to receive duplicate access requests from instruction duplicator 405 and perform a validation operation using the degraded data and the duplicate access requests. This may result in determining whether instruction verifier 413 identifies the degraded data and whether the degraded data affects each copy of the duplicate access requests. Consequently, in operation 620, instruction verifier 413 may assert a fault based on a validation indicating that instruction verifier 413 has received degraded data.Based on the confirmation of the error, the command verifier 413 may provide an indication of the confirmation to the processing core 110-1 in operation 625. Consequently, the processing core 110-1 may determine that the command verifier 413 successfully passed the test and that the dual pumping function safety mode is functioning correctly.

[0080] Likewise, in operation 615, processing core 110-1 uses response error injection 406 to randomly degrade data associated with a response from non-volatile data storage 135 based on the access request and provide the degraded data to response verifier 408. During this step, response verifier 408 may be configured to receive duplicate responses from response duplicator 416 and perform a validation operation using the degraded data and the duplicate responses. This may result in determining whether response verifier 408 identifies the degraded data and whether the degraded data affects each copy of the duplicate responses. In operation 620, response verifier 408 may assert an error based on validation indicating that response verifier 408 received degraded data.Based on the acknowledgment of the error, in operation 625, the response checker 408 may provide an indication of the acknowledgment to the processing core 110-1. Consequently, the processing core 110-1 may determine that the response checker 408 successfully passed the test and that the dual pumping function safety mode is functioning correctly.

[0081] However, in operation 620, if either the command verifier 413 or the response verifier 408 fails to acknowledge an error, or in other words, fails to identify received degraded data, the command verifier 413 and / or the response verifier 408 may not provide an acknowledgment to the processing core 110-1. Consequently, the processing core 110-1 may determine that the dual pump circuitry (e.g., functional safety controller 128) failed the test and may interrupt operations.

[0082] Fig. 7 illustrates a computing system 701 for performing cryptographic processes related to data storage access, according to one implementation of the present technology. Computing system 701 is representative of any system or collection of systems with which the various operational architectures, processes, scenarios, and sequences disclosed herein for data storage access control may be used. Computing system 701 may be implemented as a single device, system, or device, or may be implemented in a distributed manner as multiple devices, systems, or devices. Computing system 701 includes, but is not limited to, a processing system 702, a storage system 703, software 705, a communications interface system 707, and a user interface system 709 (optional).Processing system 702 is operably coupled to storage system 703, communication interface system 707, and user interface system 709. Computing system 701 may be representative of a cloud computing device, a distributed computing device, or the like.

[0083] Processing system 702 loads and executes software 705 from storage system 703. Software 705 includes and implements a secure mode control process 706 representative of any of the access request and response duplication, filtering, encryption, decryption, and statistics collection processes discussed with reference to the preceding figures. When executed by processing system 702 to provide access functions, software 705 instructs processing system 702 to operate as described herein for at least the various processes, operational scenarios, and sequences discussed in the preceding implementations. Computing system 701 may optionally include additional devices, features, or functionality that are not discussed for the sake of brevity.

[0084] Still referring to Fig.7, processing system 702 may include a microprocessor or other circuitry that retrieves and executes software 705 from memory system 703. Processing system 702 may be implemented within a single processing device, but may also be distributed across multiple processing devices or subsystems that cooperate to execute program instructions. Examples of processing system 702 include general-purpose central processing units, graphics processing units, application-specific processors and logic devices, as well as any other type of processing device, combinations, or variations thereof.

[0085] The storage system 703 may include any computer-readable storage media readable by the processing system 702 and capable of storing software 705. The storage system 703 may include volatile and non-volatile, removable and non-removable media implemented in any method or technology for storing information such as computer-readable instructions, data structures, program modules, or other data. Examples of storage media include random access data storage, read-only data storage, magnetic disks, optical disks, optical media, flash data storage, virtual data storage and non-virtual data storage, magnetic cartridges, magnetic tape, magnetic disk storage, or other magnetic storage devices, or any other suitable storage media. In no event is the computer-readable storage media a propagated signal.

[0086] In addition to computer-readable storage media, in some implementations, storage system 703 may also include computer-readable communication media over which at least some of software 705 may be communicated internally or externally. Storage system 703 may be implemented in a single storage device, but may also be implemented across multiple storage devices or subsystems that are co-located or distributed relative to one another. Storage system 703 may include additional elements, such as a controller capable of communicating with processing system 702 or possibly other systems.

[0087] The software 705 (including the security mode control process 706) may be implemented in program instructions and, among other functions, when executed by the processing system 702, may instruct the processing system 702 to operate as described with respect to the various operating scenarios, sequences, and processes presented herein. For example, the software 705 may include program instructions for selecting a cryptography mode, as described herein.

[0088] In particular, the program instructions may include various components or modules that cooperate or otherwise cooperate to perform the various processes and operating scenarios described herein. The various components or modules may be embodied in compiled or interpreted instructions, or in any other variation or combination of instructions. The various components or modules may execute in a synchronous or asynchronous manner, serially or in parallel, in a single-threaded environment or multi-threaded, or according to any other suitable execution paradigm, variation, or combination thereof. The software 705 may include additional processes, programs, or components, such as operating system software, virtualization software, or other application software.The software 705 may also include firmware or any other form of machine-readable processing instructions executable by the processing system 702.

[0089] In general, when loaded and executed on processing system 702, software 705 may transform a suitable device, system, or apparatus (of which computing system 701 is representative) from a general-purpose computing system into a special-purpose computing system tailored to provide data storage access as described herein. Indeed, encoding software 705 on storage system 703 may transform the physical structure of storage system 703. The specific transformation of the physical structure may depend on various factors in different implementations of this description.Examples of such factors may include, but are not limited to, the technology used to implement the storage media of the storage system 703, and whether the computer storage media is characterized as primary or secondary storage, as well as other factors.

[0090] For example, if the computer-readable storage media is implemented as semiconductor-based data storage, the software 705 may transform the physical state of the semiconductor data storage if the program instructions are encoded therein, such as by transforming the state of transistors, capacitors, or other discrete circuit elements that comprise the semiconductor data storage. A similar transformation may occur with respect to magnetic or optical media. Other transformations of physical media are possible without departing from the scope of the present description; the foregoing examples are provided only to facilitate the present discussion.

[0091] The communication interface system 707 may include communication links and communication devices that enable communication with other computing systems (not shown) over communication networks (not shown). Examples of links and devices that together enable communication between systems may include network interface cards, antennas, power amplifiers, radio frequency circuitry, transceivers, and other communication circuitry. The links and devices may communicate over communication media to exchange communications with other computing systems or networks of systems, such as metal, glass, air, or any other suitable communication media. The aforementioned media, links, and devices are well known and need not be discussed in detail here.

[0092] Communication between computing system 701 and other computing systems (not shown) may occur over a communication network or communication networks and according to various communication protocols, combinations of protocols, or variations thereof. Examples include intranets, internets, the Internet, local area networks, wide area networks, wireless networks, wired networks, virtual networks, software-defined networks, data center buses and backplanes, or any other type of network, combination of networks, or variations thereof. The aforementioned communication networks and communication protocols are well known and need not be discussed in detail here.

[0093] Although some examples provided herein are described in the context of a system on a chip, a processor, a processing core, a microcontroller unit, circuitry, an environment, or the like, the data storage access methods, data storage access techniques, and data storage access systems described herein are not limited to such examples and may apply to a variety of other processes, systems, applications, devices, and the like. Aspects of the present invention may be embodied as a system, method, computer program product, and other configurable systems. Accordingly, aspects of the present invention may take the form of a fully hardware embodiment, a fully software embodiment (including firmware, resident software, microcode, etc.).) or an embodiment combining software and hardware aspects, all of which may be generally referred to herein as a "circuit," "module," or "system." Furthermore, aspects of the present invention may take the form of a computer program product embodied in one or more computer-readable media having computer-readable program code embodied thereon.

[0094] Unless the context clearly requires otherwise, throughout the specification and claims, the words "comprise," "comprising," and the like are intended to be construed in an inclusive sense as opposed to an exclusive or exhaustive sense; that is, in the sense of "including, but not limited to." As used herein, the terms "connected," "coupled," or some variation thereof mean any connection or coupling, either direct or indirect, between two or more elements; the coupling or connection between the elements may be physical, logical, or a combination thereof. Furthermore, the words "herein," "foregoing," "hereinafter," and words of similar import, when used in this application, refer to this application as a whole and not to any specific portions of this application.Where the context permits, words in the above detailed description using the singular or plural number may also include the plural or singular number, respectively. The word "or" in reference to a list of two or more items covers all of the following interpretations of the word: any of the items in the list, all of the items in the list, and any combination of the items in the list.

[0095] The phrases "in some examples," "according to some examples," "in the examples shown," "in other examples," and the like generally mean that the particular feature, structure, or characteristic recited in the phrase is included in at least one implementation of the present technology and may be included in more than one implementation. Furthermore, such phrases do not necessarily refer to the same example or different examples.

[0096] The above detailed description of examples of the technology is not intended to be exhaustive or to limit the technology to the precise form disclosed above. Although specific examples of the technology are described above for illustrative purposes, various equivalent modifications are possible within the scope of the technology, as one of ordinary skill in the relevant art will recognize. For example, although processes or blocks are depicted in a given order, alternative implementations may perform routines with steps or utilize systems with blocks in a different order, and some processes or blocks may be deleted, relocated, added, subdivided, combined, and / or modified to create alternative or sub-combinations. Each of these processes or blocks may be implemented in a variety of different ways.Although processes or blocks are sometimes shown as being performed in series, these processes or blocks may instead be performed or implemented in parallel, or may be performed at different times. Furthermore, any specific numbers given here are examples only; alternative implementations may use different values ​​or ranges.

[0097] The teachings of the technology provided herein may be applied to other systems, not necessarily the system described above. The elements and acts of the various examples described above may be combined to create further implementations of the technology. Some alternative implementations of the technology may not only include additional elements to the implementations specified above, but may also include fewer elements.

[0098] These and other changes may be made to the technology in light of the above detailed description. Although the above description describes particular examples of the technology and describes the best mode contemplated, no matter how detailed the above appears in the text, the technology may be embodied in many ways. Details of the system may vary considerably in its particular implementation, although it is nevertheless encompassed by the technology disclosed herein. As stated above, the specific terminology used in describing particular features or aspects of the technology should not be construed to imply that the terminology has been redefined herein as being limited to any specific features, features, or aspects of the technology with which that technology is associated.In general, the terms used in the following claims should not be construed as limiting the technology to the specific examples disclosed in the specification unless the above detailed description section explicitly defines such terms. Consequently, the true scope of the technology includes not only the disclosed examples, but all equivalent ways of practicing or implementing the technology under the claims.

[0099] To reduce the number of claims, certain aspects of the technology are presented below in certain claim forms, but the applicant contemplates the various aspects of the technology in any number of claim forms. For example, although only one aspect of the technology is recited as a computer-readable medium claim, other aspects may also be recited as a computer-readable medium claim or in other forms, such as embodied in a means-plus-function claim. Any claims intended to be treated under 35 USC § 112(f) begin with the words "means for," but use of the term "for" in any other context is not intended to invoke treatment under 35 USC § 112(f).Accordingly, the applicant reserves the right to pursue additional claims after the filing of this application to pursue such additional claim forms either in this application or in a continuation application.

Claims

[1] Device comprising: a data storage backup controller configured to operate in a first functional safety mode or a second functional safety mode; a backup mode selection controller coupled to the data storage backup controller; and a data storage interface controller coupled to the data storage backup controller and the backup mode selection controller and configured to couple to a non-volatile data storage; where the backup mode selection controller is configured to: determine a number of upcoming access requests associated with the data storage backup controller; determine a number of incoming responses from the non-volatile data storage to the data storage backup controller; and to select between the first functional safety mode and the second functional safety mode based on the number of upcoming access requests and / or the number of incoming responses. [2] The apparatus of claim 1, wherein the backup mode selection controller is configured to: instruct the data storage backup controller to operate in the first functional safety mode based on the number of incoming responses exceeding a first threshold number; and instruct the data storage backup controller to operate in the second functional safety mode based on the number of pending access requests exceeding a second threshold number. [3] The apparatus of claim 2, wherein the data storage backup controller is configured to duplicate a request and / or a response in the first functional security mode and to compare copies of the request and / or the response. [4] The apparatus of claim 3, wherein the data storage backup controller is configured to compare at least a portion of a decrypted response with a message authentication code (MAC) value in the second functional security mode. [5] The apparatus of claim 3, wherein the data storage backup controller is configured to, in the first functional security mode: to duplicate the request; encrypt information associated with each copy of the request; and to supply a subset of the copies of the request to the data storage interface controller. [6] The apparatus of claim 5, wherein the data storage backup controller is configured to, in the first functional security mode: to duplicate the answer; decrypt information associated with each copy of the response; and to supply a subset of the copies of the response to one or more processing cores. [7] The apparatus of claim 1, wherein the pending access requests comprise read requests and write requests, and wherein the incoming responses comprise data or instructions corresponding to the pending access requests. [8] System comprising: one or more processing cores; an interconnect coupled to the one or more processing cores; a data storage backup controller; a backup mode selection controller coupled to the data storage backup controller; and a data storage interface controller coupled to the data storage backup controller and the backup mode selection controller and configured to couple to a non-volatile data storage; where the backup mode selection controller is configured to: determine a number of upcoming access requests associated with the data storage backup controller; determine a number of incoming responses from the non-volatile data storage to the data storage backup controller; and to control which cryptographic functional security process is applied to a request and / or a response based on the number of upcoming access requests and / or the number of incoming responses. [9] The system of claim 8, wherein to control which cryptographic functional security process is applied by the data storage security controller, the security mode selection controller is configured to: instruct the data storage security controller to perform a first cryptographic functional security process on the request and / or the response based on the number of incoming responses exceeding a first threshold number; and instruct the storage security controller to perform a second cryptographic functional security process on the request and / or the response based on the number of upcoming access requests exceeding a second threshold number. [10] The system of claim 9, wherein the first cryptographic functional security process comprises duplicating the request and / or the response. [11] The system of claim 10, wherein the second cryptographic functional security process comprises comparing at least a portion of a decrypted response with a message authentication code (MAC) value. [12] The system of claim 10, wherein to perform the first cryptographic functional security process, the data storage backup controller is configured to: duplicate the request to create copies of the request; to encrypt information associated with each of the copies of the request; and to supply a subset of the copies of the request to the data storage interface controller. [13] The system of claim 12, wherein to perform the first cryptographic functional security process, the data storage backup controller is configured to: duplicate the answer to create copies of the answer; decrypt information associated with each of the copies of the response; and to supply a subset of the copies of the response to the one or more processing cores. [14] The system of claim 8, wherein the pending access requests comprise read requests and write requests, and wherein the incoming responses comprise data or instructions corresponding to the pending access requests. [15] Procedure comprising: Receiving access requests for data stored in a non-volatile data storage device from one or more processing cores; Determining a number of upcoming access requests of the access requests associated with the non-volatile data storage device; Determining a number of incoming responses from the non-volatile data storage device; and Selecting which cryptographic functional security process to apply to a request and / or a response based on the number of upcoming access requests and / or the number of incoming responses. [16] The method of claim 15, wherein controlling which cryptographic functional security process is to be applied comprises: Selecting to apply a first cryptographic functional security process to the request and / or the response based on the number of incoming responses exceeding a first threshold number; and Selecting to apply a second cryptographic functional security process to the request and / or the response based on the number of upcoming access requests exceeding a second threshold number. [17] The method of claim 16, wherein applying the first cryptographic security process comprises duplicating the request and / or the response and comparing copies of the request and / or the response, and wherein applying the second cryptographic security process comprises comparing at least a portion of a decrypted response with a message authentication code (MAC) value. [18] The method of claim 17, wherein applying the first cryptographic functional security process comprises: Duplicate the requirement; Encrypting information associated with each copy of the request; and Feeding a subset of the copies of the request to a data storage interface controller. [19] The method of claim 18, wherein applying the first cryptographic functional security process further comprises: Duplicate the answer; Decrypting information associated with each copy of the response; and Supplying a subset of the copies of the response to the one or more processing cores. [20] The method of claim 15, wherein the upcoming access requests comprise read requests and write requests, and wherein the incoming responses comprise data or instructions corresponding to the upcoming access requests.