Hardware Configuration Module for Dynamic Life Cycle Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current micro-controllers face challenges in dynamically configuring security settings, as once security configurations are programmed, they become non-alterable, making it difficult to analyze malfunctions or test security features during development and diagnostics.
Innovation Solution
A processing system with a hardware configuration module that allows overwriting of life cycle data stored in a one-time programmable memory, enabling dynamic security configuration changes by advancing the life cycle stage through software commands, while ensuring security through keyword verification and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security configuration data are programmed into non-volatile memory, then security protection is enforced, but the configuration becomes non-alterable and prevents further access
Solution Approach 1:
The configuration memory is segmented into two distinct parts: a first non-volatile memory for storing alterable security configuration data and a second non-volatile memory for storing non-alterable security configuration data. This segmentation allows the system to maintain both alterable and non-alterable configuration capabilities simultaneously, resolving the contradiction between security enforcement and configuration flexibility.
2Reliability
If debug interface is deactivated for security, then security function is activated, but malfunction analysis becomes difficult
Solution Approach 1:
The security configuration is made dynamic through the first non-volatile memory, which can be altered even after initial programming. This allows the debug interface deactivation status to be changed based on operational needs - deactivated during normal operation for security, but reactivated when malfunction analysis is required, thus resolving the contradiction between security enforcement and diagnostic capability.
3Reliability
If configuration data are made non-alterable, then protection is always active, but dynamic configurability is lost
Solution Approach 1:
The configuration system is divided into alterable and non-alterable portions stored in separate memory regions. The first non-volatile memory stores configuration data that can be modified to enable dynamic configurability, while the second non-volatile memory stores immutable configuration data that ensures continuous protection. This dual-memory architecture simultaneously provides both protection reliability and dynamic adaptability.
Data Source
Figure 1~2
Figure 3~4
Figure 5~6
AI summary
A processing system is described. The processing system comprises a processing unit (102), and at least one hardware block (110) configured to change operation as a function of life cycle data (LCD). Specifically, a one-time programmable memory (104; 126) comprises original life cycle data (OLCD) and a hardware configuration module (108) reads the original life cycle data (OLCD) from the one-time programmable memory (104; 126) and provides the original life cycle data (OLCD) to the at least one hardware block (110). Specifically, the hardware configuration module (108) comprises a register providing the life cycle data (LCD) to the at least one hardware block (110) . The hardware configuration module (108) is configured to: - store the original life cycle data (OLCD) in the register, thereby providing the original life cycle data to the at least one hardware block (110); and - receive a command (CMD) from the processing unit (102), wherein the command (CMD) comprising a write request for storing new life cycle data in the register, thereby providing the new life cycle data to the at least one hardware block (110).