Hardware Security Module With Dedicated Error Detection Circuit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transmission and reception techniques lack functional safety measures to protect against data errors caused by hardware faults or errors corrected using error-correcting codes, leading to potential security risks in secure data transmission.

Innovation Solution

A semiconductor device with a hardware security module circuit and an error detection circuit that performs authentication and error detection processes, where the error detection circuit is accessible only by the hardware security module circuit, ensuring secure data transmission and reception while preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing data transmission techniques are used, then data can be transmitted between devices, but functional safety measures such as error detection and prevention against hardware faults are not implemented

Engineering Contradiction:
Improvefunctional safetyVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into distinct functional modules: a hardware security module circuit for authentication processes and an error detection circuit for error detection processes. Each circuit has dedicated memory areas, creating segmented functional units that work together to provide both security and reliability without requiring a complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The error detection circuit acts as an intermediary between the hardware security module circuit and the external environment. It monitors and validates data processed by the security module, providing an additional layer of functional safety without interfering with the core security operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If error-correcting code techniques are introduced for cryptanalytic purposes, then encryption/decryption capability is enhanced, but functional safety measures are still not provided

Engineering Contradiction:
Improveerror detection capabilityVSAvoidcircuit configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent separates error detection functionality from error correction functionality. The error detection circuit independently validates data integrity without attempting to correct errors, maintaining a clear functional division that simplifies the overall system architecture while providing robust error detection capabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The error detection circuit is designed to work with various authentication processes in the hardware security module, providing universal error detection capability across different security operations without requiring separate detection circuits for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the error detection circuit memory area is made accessible only by the hardware security module circuit, then data confidentiality is protected, but access flexibility is reduced

Engineering Contradiction:
Improvedata confidentialityVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

Different memory areas are assigned different access permissions based on their specific functional requirements. The error detection circuit has dedicated memory areas that are accessible only by the hardware security module circuit for maintaining confidentiality, while other memory areas may have different access controls appropriate to their functions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3486832B1Semiconductor device, authentication system, and authentication method
Publication Date: 2021.07.21 RENESAS ELECTRONICS CORP
  • EP3486832B1 patent drawingFigure 1
  • EP3486832B1 patent drawingFigure 2~3
  • EP3486832B1 patent drawingFigure 4~5

AI summary

Provided is a semiconductor device which can perform secure data transmission/reception considering functional safety. The semiconductor device includes a hardware security module circuit which performs an authentication process and an error detection circuit used to perform an error detection process at least on first data which is processed in the hardware security module circuit. A memory area associated with the error detection circuit is configured to be accessible only by the hardware security module circuit when the error detection process is performed at least on the first data.