Hardware Configuration Circuit for Secure Data Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current processing systems in automotive applications face challenges in ensuring the correct configuration and verification of configuration data, which can lead to malfunctions, safety threats, and security breaches due to errors or intentional alterations in configuration data during the configuration phase.
Innovation Solution
The implementation of a configuration data client circuit system with redundant flip-flops or latches, a hardware configuration circuit that reads and transmits configuration data from non-volatile memory, and a signature verification mechanism to ensure data integrity and authenticity, using error detection and correction codes to verify the accuracy of configuration data stored in client circuits.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If configuration data is stored in non-volatile memory and transmitted to client circuits, then the processing system can be configured with multiple functionalities, but errors or intentional alterations in configuration data can lead to malfunctions, safety threats, and security breaches
Solution Approach 1:
The patent applies preliminary action by calculating and storing signature data (checksums) in advance during the configuration data creation phase. The signature data is computed from the configuration data using a cryptographic hash function and stored alongside the configuration data in non-volatile memory. This preliminary computation enables subsequent verification without requiring complex real-time validation logic during system operation.
Solution Approach 2:
The patent implements feedback through a verification mechanism where the processing unit reads both configuration data and signature data from non-volatile memory, recalculates the signature from the configuration data, and compares it with the stored signature. This closed-loop feedback system detects any alterations or errors in configuration data by identifying mismatches between calculated and stored signature values, thereby ensuring configuration integrity before system operation.
2Adaptability or versatility
If configuration data is distributed to multiple client circuits, then the system can support complex functionalities, but verification of correct configuration becomes difficult
Solution Approach 1:
The patent applies copying by creating a cryptographic fingerprint (signature data) of the configuration data. Instead of verifying the entire configuration data set across multiple client circuits, the system copies the compact signature data to a verification register and compares it with a recalculated signature. This copying approach transforms a complex verification problem into a simple comparison operation, making it feasible to verify configuration integrity even in systems with multiple client circuits.
3Adaptability or versatility
If the processing system increases complexity to meet automotive requirements, then more functionalities can be implemented, but power consumption and calculation requirements increase
Solution Approach 1:
The patent reduces power consumption during operation by performing the computationally intensive signature calculation in advance during system initialization or configuration loading. The cryptographic hash function is executed once when configuration data is loaded from non-volatile memory, rather than continuously during system operation. This preliminary computation approach minimizes ongoing power requirements while maintaining security verification capabilities.
Solution Approach 2:
The patent replaces complex mechanical verification mechanisms with cryptographic mathematical operations. Instead of using hardware checksums, parity bits, or redundant configuration copies that would require extensive comparison logic across multiple client circuits, the system uses cryptographic hash functions to generate compact signature data. This substitution reduces the computational burden during verification to a simple hash calculation and comparison, significantly lowering power consumption compared to traditional verification methods.
Data Source
AI summary
A hardware configuration circuit can sequentially read data packets from a non-volatile memory. For a first data packet, the circuit is configured to store the configuration data and the address included in the data packet in the register, select a target configuration data client circuit as a function of the address included in the first data packet, transmit a first data signal that includes the configuration data included in the first data packet to the target configuration data client circuit, receive a second data signal that includes configuration data stored in the target configuration data client circuit and the address associated with the target configuration data client circuit, and compare the configuration data and address received from the target configuration data client circuit with the configuration data and address stored in the register.


