Cryptographic Component Binding for SoC Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Complex System-on-Chip (SoC) designs face compatibility and interoperability issues due to separate entities providing software and hardware components, leading to diminished performance when non-original components are reintegrated, potentially with lower quality or unauthorized software.
Innovation Solution
A method involving cryptographic verification to ensure original component compatibility by generating and comparing 'Glue Bits' using an anchor chipset, which binds components cryptographically, allowing or inhibiting operation based on matching verification values stored in one-time programmable memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If components are separated and re-integrated with non-original components, then device adaptability increases, but device reliability deteriorates due to use of lesser-quality components or unauthorized software
Solution Approach 1:
The patent applies preliminary action by pre-establishing cryptographic binding between the anchor chipset and other components during original device assembly. Verification values are generated and stored in one-time programmable memory before the device is put into service. This pre-configured cryptographic relationship enables automatic verification of component authenticity upon each device startup, preventing the integration of non-original components while maintaining adaptability for legitimate component replacements.
2Reliability
If cryptographic verification is implemented to ensure component authenticity, then device reliability improves, but device complexity increases due to additional verification mechanisms
Solution Approach 1:
The patent applies segmentation by dividing the verification system into distinct functional modules: an anchor chipset that serves as the root of trust, separate verification logic in the second component, and one-time programmable memory for storing verification values. This modular segmentation isolates the cryptographic verification functionality from the main system operations, enabling reliable component authentication while managing complexity through clear separation of concerns and dedicated verification hardware.
Data Source
Figure 1
Figure 2A~2B
Figure 3
AI summary
A method of operating a computer system includes: obtaining, at the computer system, verification-input information associated with each of multiple hardware components of the computer system; cryptographically processing, at the computer system, the verification- input information to obtain a cryptographic result; and determining, at the computer system, whether to allow or inhibit, depending upon a comparison of the cryptographic result with a verification value, further operation of at least one of the hardware components.