Data Processing Security Unit Falsification Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital content protection systems are vulnerable to software falsification and data alteration, leading to security breaches and unauthorized use, as they fail to detect changes in software and data processing, resulting in increased costs and decreased product reliability.

Innovation Solution

A data processing apparatus with a security unit that includes an encryption means for decoding encrypted signals, a compression means for compressing access signals, and a comparison means for detecting falsification by comparing the compression result with a previously-obtained expectation value, thereby preventing unjust access and data alteration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a debugger is coupled to the CPU and data is sent directly to the security protection area, then ease of operation for debugging is improved, but security against unjust access deteriorates

Engineering Contradiction:
Improvedebugging capabilityVSAvoidsecurity protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A compression means is introduced as an intermediary component between the CPU and the security protection area. This compression means compresses access signals before they reach the security area, creating an additional layer that prevents direct access and debugger coupling, thereby maintaining security while allowing legitimate debugging operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the security protection area is integrated into a single chip, then security against unjust access is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security protection area, compression means, and CPU are integrated into a single chip structure. This merging approach consolidates multiple functions into one unified device, improving security by preventing external debugger access while managing complexity through systematic integration of components

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If compression means is added to compress access signals, then detection of software falsification is improved, but device complexity increases

Engineering Contradiction:
Improvefalsification detectionVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The compression means performs preliminary compression of access signals before they reach the security protection area. By pre-compressing the signals, the system creates a verifiable transformation that can be used to detect falsification, enabling precise detection while managing complexity through proactive signal processing

Inventive Principle:
Principle #10Preliminary action

4Ease of manufacture

If authentication and decryption functions are implemented in software, then ease of manufacture is improved, but vulnerability to falsification increases

Engineering Contradiction:
Improvesoftware implementationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system replaces pure software authentication and decryption with a hybrid approach that incorporates hardware-based compression means and security protection areas. This substitution of mechanical/hardware elements for software functions reduces vulnerability to falsification while maintaining manufacturability through integrated chip design

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9092619B2Data processing apparatus
Publication Date: 2015.07.28 RENESAS ELECTRONICS CORP
  • US9092619B2 patent drawing
  • US9092619B2 patent drawing
  • US9092619B2 patent drawing

AI summary

A data processing apparatus is provided, which detects falsification of software to data and rewriting of the data. The data processing apparatus according to an embodiment of the present invention comprises a security unit which has an encryption circuit for decrypting an encrypted signal including secrecy data. The security unit includes a compression circuit which compresses an access signal used in accessing the security unit and outputs the compression result, and a comparison circuit which compares the compression result outputted from the compression circuit with a previously-calculated expectation value of the compression result of the access signal.