Cryptographic Circuit Segmentation for Automotive Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The transmission of cryptographically secured data from peripheral devices to hardware security modules in automotive electronic control units causes delays and increased processor power consumption, compromising security and efficiency.

Innovation Solution

A cryptographic circuit is configured with a secure area for high-resistance operations and an unsecured area for lower-resistance operations, with data transmission occurring through a secure channel that maintains the resistance level of the secure area, allowing the secure area to control and manage data processing in the unsecured area.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic data is transmitted from peripheral devices to hardware security modules, then data security is maintained, but transmission delay increases and processor power consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidtransmission delay
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The cryptographic circuit is divided into two distinct sections: a secure area with high attack resistance for sensitive operations, and an unsecured area with lower attack resistance for general processing. This segmentation allows cryptographic operations to be distributed appropriately, reducing the need for frequent transmissions to the hardware security module while maintaining security for critical data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A transmission area with intermediate security characteristics is introduced between the secure and unsecured areas. This intermediary zone facilitates efficient data exchange while maintaining appropriate security boundaries, allowing cryptographic data to be processed in the unsecured area without requiring constant transmission to the highly secure hardware security module.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic data is transmitted from peripheral devices to hardware security modules, then data security is maintained, but processor power consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessor power consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

By segmenting the cryptographic circuit into secure and unsecured areas, processing tasks can be distributed to the most appropriate location. Routine cryptographic operations can be performed in the unsecured area using available resources, reducing the frequency of power-intensive transmissions to the hardware security module while maintaining security for sensitive operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The unsecured area is empowered to perform cryptographic operations independently using the cryptographic circuit resources available in that area. This self-service capability reduces dependency on the hardware security module for routine operations, thereby reducing processor power consumption associated with data transmission and centralized processing.

Inventive Principle:
Principle #25Self-service

3Reliability

If cryptographic operations are centralized in hardware security modules, then security is maximized, but processing efficiency decreases

Engineering Contradiction:
ImprovesecurityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The cryptographic circuit is segmented into secure and unsecured areas, each capable of performing cryptographic operations appropriate to their security level. This distribution of processing capability increases overall system productivity by handling more operations in parallel while the secure area maintains security for critical functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Both the secure area and unsecured area are equipped with cryptographic circuit capabilities, making the system multi-functional. The unsecured area can handle routine cryptographic operations independently, while the secure area handles sensitive operations, creating a universal system that can process various types of cryptographic tasks efficiently across different security requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11308240B2Cryptographic circuit and data processing
Publication Date: 2022.04.19 INFINEON TECHNOLOGIES AG
  • US11308240B2 patent drawing
  • US11308240B2 patent drawing

AI summary

A method for cryptographic data processing by means of a circuit comprises using a first circuit section to perform a first cryptographic operation in order to obtain first cryptographic data. The method further includes transmitting the first cryptographic data to a second circuit section via a transmission area of the circuit that physically separates the second circuit section from the first circuit section and whose resistance to attacks is at most as high as the resistance of the first circuit section. The method includes using the second circuit section to perform a second cryptographic operation using the first cryptographic data in order to obtain second cryptographic data.