Configuration Data Client for Dynamic Security in Automotive Microcontrollers
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current micro-controllers in automotive applications face challenges in dynamically configuring security settings, as once security features are programmed, they become immutable, making it difficult to analyze malfunctions or modify configurations in the field.
Innovation Solution
A processing system with configuration data clients and a non-volatile memory that allows for dynamic configurability through data packets with attribute fields, enabling selective writing or reading of configuration data based on identification signals, allowing for temporary overwriting of security configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security configuration data is stored in non-volatile memory and made immutable after programming, then security protection is ensured, but the ability to analyze malfunctions and modify configurations in the field is lost
Solution Approach 1:
The patent divides configuration data into two distinct parts: immutable security configuration data stored in non-volatile memory and mutable operational parameters stored in volatile memory. This segmentation allows security features to maintain their protective integrity while operational settings remain dynamically adjustable for debugging and analysis purposes.
Solution Approach 2:
The patent introduces a configuration data client as an intermediary component that mediates between the immutable non-volatile memory and the volatile memory. This intermediary enables selective reading and writing of configuration data, allowing the system to maintain security while permitting controlled modifications for analysis and testing.
2Reliability
If the debug interface is deactivated through configuration, then security is improved, but the ability to control and test processing system resources is lost
Solution Approach 1:
The patent implements dynamic control of the debug interface through configuration data clients that can be selectively enabled or disabled. The system transitions from a static security state to a dynamic state where the debug interface can be activated when needed for testing and deactivated when security is prioritized, allowing flexible adaptation between these opposing requirements.
Solution Approach 2:
The patent applies local quality by enabling different access levels for different parts of the processing system. The debug interface can be selectively enabled for specific resources or functions while maintaining security protections for other critical areas, allowing targeted debugging without compromising overall system security.
3Reliability
If configuration data is made non-alterable after programming, then security protection is activated, but the ability to modify settings for testing and development is restricted
Solution Approach 1:
The patent segments configuration data into security-critical immutable portions and testing-friendly mutable portions. This allows the system to maintain secure security configurations while permitting flexible modifications to operational parameters during testing and development phases, eliminating the need for multiple hardware units for different test scenarios.
Solution Approach 2:
The patent utilizes parameter changes by allowing the system to transition between different operational modes through configuration data clients. The same hardware can be reconfigured for different testing scenarios by modifying operational parameters while maintaining the underlying security configuration, enabling versatile testing without compromising security integrity.
Data Source
AI summary
A hardware configuration circuit configured to sequentially read data packets and transmit the data to a configuration data client. The configuration data client configured to receive a first and a second set of configuration data addressed to a respective address. The client is configured to store the first set of configuration data in a register and verify whether further configuration data may be written to the respective register as a function of a type identification signal. In response, the configuration data client is configured to overwrite the first set of configuration data by storing the second set of configuration data in the respective register or maintain the first set of configuration data by inhibiting storage of the second set of configuration data received in the respective register. The configuration corresponding to verifying whether further configuration data may be written to the register.


