On-Die Cryptographic Unit for Secure Microprocessor Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current microprocessors are inadequate in executing general purpose instructions within a secure execution environment due to limitations in existing security features, which can be compromised and are susceptible to snooping and tampering, especially when using external chipsets and system buses.

Innovation Solution

A microprocessor with a secure non-volatile memory and cryptographic unit, isolated from system bus resources, enables execution of secure applications by encrypting and decrypting code using asymmetric key algorithms, ensuring secure execution within a private bus environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If external chipsets and system buses are used for microprocessor execution, then device complexity is reduced and ease of manufacture is improved, but security is compromised due to susceptibility to snooping and tampering

Engineering Contradiction:
Improveease of manufactureVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The microprocessor is segmented into distinct secure and non-secure execution environments. The secure execution environment includes dedicated secure registers, secure instruction streams, and isolated execution units that are physically separated from the non-secure system bus interfaces. This segmentation allows the processor to manufacture using standard external chipsets while maintaining isolated secure paths that prevent snooping and tampering.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary secure execution environment is introduced between the external system bus and the critical processing functions. This intermediary layer includes secure memory interfaces and encrypted data paths that mediate all communications between the external bus and internal secure resources, preventing direct access and potential tampering while still allowing external connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a secure execution environment is implemented within the microprocessor, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure execution environment is merged with the existing microprocessor architecture rather than being implemented as a separate external device. Secure registers, encryption units, and isolated execution paths are integrated into the processor core, combining security functions with general-purpose computing resources. This merging reduces overall system complexity by eliminating the need for separate secure coprocessors or external security chips.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The microprocessor is designed with universal resources that can operate in both secure and non-secure modes. Execution units, memory interfaces, and I/O controllers are configured to handle both encrypted secure instructions and standard non-secure instructions, allowing a single device to perform multiple functions without requiring separate dedicated hardware for each mode.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure code is isolated from system bus resources, then security is improved by preventing snooping, but access speed may be reduced

Engineering Contradiction:
ImprovesecurityVSAvoidaccess speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The secure execution environment is nested within the microprocessor core, with secure registers and instruction streams embedded within the broader processor architecture. This nesting allows secure code to access critical processing resources through direct internal pathways that are hierarchically organized, maintaining high-speed access while preventing exposure to external system bus resources. The nested structure enables secure data to flow through multiple layers of protection without requiring external memory accesses.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS9002014B2On-die cryptographic apparatus in a secure microprocessor
Publication Date: 2015.04.07 VIA TECH INC
  • US9002014B2 patent drawing
  • US9002014B2 patent drawing
  • US9002014B2 patent drawing

AI summary

An apparatus providing for a secure execution environment, including a secure non-volatile memory and a microprocessor. The secure non-volatile memory stores a secure application program. The secure application program is encrypted according to a cryptographic algorithm. The microprocessor is coupled to the secure non-volatile memory via a private bus and to a system memory via a system bus. The microprocessor executes non-secure application programs and the secure application program. The non-secure application programs are accessed from the system memory via the system bus. Transactions over the private bus are isolated from the system bus and corresponding system bus resources within the microprocessor. The microprocessor has a cryptographic unit, disposed within execution logic. The cryptographic unit is configured to encrypt the secure application program for storage in the secure non-volatile memory, and is configured to decrypt the secure application program for execution by the microprocessor.