Distributed Security Controller for SoC Subsystems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In large data processing systems, especially system-on-a-chip (SoC) systems, security components from various vendors lack a standard method for managing security states, and existing security controllers are isolated and cannot leverage their trustworthiness to enhance the security of the entire SoC platform, leading to potential security vulnerabilities and power management inefficiencies.

Innovation Solution

Implementing a data processing system with local security controllers for each subsystem, allowing immediate response to local state conditions, such as fault detection and tamper events, and enabling independent security policy enforcement, which notifies a central security controller while preventing compromised subsystems from affecting the rest of the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single security controller is used to manage all security components in the system, then centralized security management is achieved, but a security failure in one subsystem affects all security components system-wide

Engineering Contradiction:
Improvesecurity controller architectureVSAvoidsystem-wide security stability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the monolithic security controller into multiple independent regional security controllers, each responsible for a specific subsystem. This segmentation isolates security failures to individual regions, preventing system-wide propagation while maintaining centralized coordination through the master security controller.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The master security controller acts as an intermediary that coordinates between multiple regional security controllers and the rest of the system. It receives security state information from regional controllers and distributes security policies, enabling centralized management without direct coupling between subsystems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of energy

If security components are powered off for power savings, then power consumption is reduced, but security response time increases when security events occur

Engineering Contradiction:
Improvepower consumptionVSAvoidsecurity response speed
Core Design Contradiction:
Loss of energyVSSpeed

Solution Approach 1:

Each regional security controller is designed to autonomously detect security events and execute security policies without requiring wake-up signals or external intervention. This self-service capability ensures immediate security response even when the controller is in a low-power state, as the controller can rapidly transition to active state upon detecting security-relevant events.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If a centralized security state machine is used to manage all security components, then unified security policy enforcement is achieved, but lack of standard methods for third-party security components reduces adaptability

Engineering Contradiction:
Improvecompatibility with third-party security componentsVSAvoidsecurity state management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The regional security controllers are designed with universal interfaces and standardized security state machines that can work with security components from different vendors. This universality allows the system to accommodate third-party security components without requiring vendor-specific integration, while the standardized state management reduces overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11023591B2Data processing system having distributed security controller with local control and method for securing the data processing system
Publication Date: 2021.06.01 NXP BV
  • US11023591B2 patent drawing
  • US11023591B2 patent drawing
  • US11023591B2 patent drawing

AI summary

A data processing system includes a plurality of subsystems, a plurality of local security controllers, and a central security controller. Each subsystem of the plurality of subsystems has a security component for providing a security function. A local security controller corresponds to each one of the subsystems. Each local security controller ensures compliance of the security component with local security policies of the subsystem to which the local security controller corresponds. The central security controller is coupled to the local security controller of each of the plurality of subsystems. The central security controller ensures data processing system compliance with system wide security policies. In the event of a detected security violation, the local security controller may respond automatically, without involvement of the central security controller. A method for securing the data processing system is also provided.