Guard CPU Secure Boot Sequence On-Chip Memory Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In system-on-chip (SoC) integrated circuits, existing technologies face challenges in securely handling data processing and preventing unauthorized access during the boot sequence, as the verifying functionality of clients within the chip may be suspended, making it difficult to prevent unauthorized access to on-chip memory.
Innovation Solution
A method and system that utilize a guard CPU to monitor chip operations, enable and disable decoding functionality, and establish a handshake protocol to ensure secure access to on-chip memory by enforcing a strong dependency protocol, with the guard CPU disabling and enabling chip functionality based on successful boot sequence completion and communication of acknowledgments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If verifying functionality of clients within the chip is suspended during boot sequence, then boot process can be simplified and faster, but unauthorized access to on-chip memory becomes possible
Solution Approach 1:
The guard CPU performs preliminary security verification actions during the boot sequence before enabling normal client operations. It monitors bus transactions and verifies authorization credentials in advance, establishing security controls before the vulnerable state occurs.
Solution Approach 2:
The guard CPU acts as an intermediary security monitor between unauthorized external entities and the on-chip memory during boot. It intercepts and monitors bus transactions, creating a protective layer that prevents unauthorized access even when client verification is suspended.
2Productivity
If multiple clients access memory through memory bus simultaneously, then data processing capability increases, but unauthorized tapping and monitoring becomes more difficult to detect
Solution Approach 1:
The guard CPU continuously monitors bus transactions and provides feedback about authorized versus unauthorized access patterns. It tracks memory access sequences and compares them against expected behavior, enabling detection of unauthorized tapping even during concurrent client operations.
Solution Approach 2:
The guard CPU serves as an intermediary monitoring layer between the memory bus and external observers. It intercepts and analyzes bus transactions, creating a protective barrier that prevents unauthorized entities from directly monitoring memory access patterns while allowing legitimate concurrent access.
3Reliability
If guard CPU monitors all bus transactions, then security coverage is maximized, but processing delay and performance overhead increases
Solution Approach 1:
The guard CPU applies partial monitoring by focusing security verification on critical boot sequence transactions and high-value memory regions rather than continuously monitoring all bus traffic. This selective approach maintains essential security coverage while reducing processing overhead and delay.
Data Source
AI summary
A method for securely handling processing of information may include deactivating within a chip, at least one of a plurality of functions that accesses an on-chip memory and generates output data from input data during operation of the chip. Configuration settings that provide maximum performance when accessing the on-chip memory may be determined using an enabled one of the plurality of functions. Access to the on-chip memory may be enabled using the determined configuration settings during the operation of the chip. Access to the on-chip memory by the plurality of functions that accesses the on-chip memory and generates the output data from the input data may be activated during operation of the chip. The on-chip memory may be accessed using the determined configuration settings by the at least one of the plurality of functions subsequent to the activating.


