Bus Security Processor Disrupting Unauthorized Peripheral Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic systems lack effective methods to secure access to peripheral devices over bus interfaces, allowing unauthorized transactions to occur, which can compromise data security.

Innovation Solution

A processor is configured to disrupt unauthorized transactions by forcing dummy values on bus lines such as data, clock, and chip-select lines, overriding the values written by bus-master devices, thereby preventing unauthorized access to peripheral devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a processor forces dummy values on bus lines to disrupt unauthorized transactions, then security against unauthorized access is improved, but the complexity of the system increases due to parallel intervention mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device is integrated into the existing bus architecture by sharing common bus lines (data, clock, chip-select) with the bus-master device and peripheral device. The processor combines the security monitoring function with the existing bus interface, eliminating the need for separate dedicated security hardware and reducing overall system complexity while maintaining security functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The processor acts as an intermediary security device that monitors and controls bus transactions by forcing dummy values on bus lines. It intervenes in the communication between the bus-master device and peripheral device, using the existing bus infrastructure as a mediator to enforce security policies without requiring additional physical connections or complex external security hardware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If additional pins or interconnections are added to secure bus access, then security control capability is improved, but the device complexity and cost increase

Engineering Contradiction:
Improvesecurity controlVSAvoidnumber of pins and interconnections
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The existing bus lines (data, clock, chip-select) are made multi-functional by enabling the processor to force dummy values on them for security purposes while maintaining their original communication functions. This universal use of existing infrastructure provides security control capability without adding new pins or interconnections, avoiding increased device complexity and cost.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security device utilizes the existing bus infrastructure and signals to enforce security policies. By self-service using the already-present data, clock, and chip-select lines, the system achieves security control without requiring external security hardware or additional physical connections, thereby avoiding increased complexity and cost.

Inventive Principle:
Principle #25Self-service

3Reliability

If the processor forces dummy values indefinitely until reset, then security protection is maintained, but the loss of time for system recovery increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem recovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security disruption duration is made dynamic rather than static. The processor can force dummy values indefinitely for severe security violations, or for a finite time period for lesser violations, or enable graceful resumption when appropriate. This dynamic adjustment of disruption duration allows the system to balance security protection with minimal recovery time based on the specific security threat level.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10095891B2Secure access to peripheral devices over a bus
Publication Date: 2018.10.09 NUVOTON
  • US10095891B2 patent drawing
  • US10095891B2 patent drawing
  • US10095891B2 patent drawing

AI summary

An apparatus includes an interface and a processor. The interface is configured for communicating over a bus. The processor is configured to disrupt on the bus a transaction in which a bus-master device attempts to access a peripheral device without authorization, by forcing one or more dummy values on at least one line of the bus in parallel to at least a part of the transaction.