Configurator for Secure Feature and Key Management in ICs

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current system-on-a-chip configurations are inflexible and costly due to the need for multiple fuses and programming steps, and secure key management is limited by the use of one-time programmable memory, requiring secure key loading in a controlled facility.

Innovation Solution

A configurator system for integrated circuits with a security manager core that manages feature and key mappings, allowing for flexible configuration and secure key management, enabling dynamic configuration changes across the chip lifecycle, including after manufacturing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If one-time programmable memory is used for chip configuration, then security is improved, but flexibility is worsened due to the one-way programming process

Engineering Contradiction:
ImprovesecurityVSAvoidconfiguration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic configuration system where the security manager can modify fuse settings multiple times throughout the chip lifecycle. The configurator enables runtime reconfiguration by loading different configuration data into the security manager, allowing the system to adapt its configuration state without requiring physical access or secure facility programming.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent pre-provisions redundant or spare fuse bits within the one-time programmable memory during manufacturing. These additional fuses are prepared in advance and can be combined through logical operations (such as exclusive-OR) to modify previous settings, enabling flexibility without requiring secure facility access during operation.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If redundant fuses are added to modify previous settings, then flexibility is improved, but device complexity and real estate are worsened

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidnumber of fuses
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The security manager serves multiple functions: it manages secure keys, controls feature enabling/disabling, and performs configuration modifications. By consolidating these functions into a single security manager core, the patent avoids the need for separate redundant fuse structures for each configuration modification capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Instead of adding physical redundant fuses, the patent creates a logical copy of configuration capabilities through the security manager. The security manager stores configuration data in memory and uses logical operations to simulate the effect of multiple fuse settings, eliminating the need for additional physical fuse elements.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If multiple programming steps are performed to configure chips, then configuration flexibility is improved, but manufacturing cost and time are worsened

Engineering Contradiction:
Improveconfiguration optionsVSAvoidconfiguration speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The security manager autonomously manages configuration updates without requiring external programming equipment or secure facility access. The system can self-reconfigure by loading configuration data through normal operational interfaces, eliminating the need for multiple sequential programming steps and enabling parallel configuration operations.

Inventive Principle:
Principle #25Self-service

4Reliability

If secure key loading is performed in a secured facility, then security is improved, but ease of operation is worsened due to facility requirements

Engineering Contradiction:
Improvekey securityVSAvoidkey loading convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security manager acts as an intermediary that receives and verifies configuration data and keys through normal operational interfaces. It performs cryptographic verification and secure storage internally, allowing key loading to occur outside secure facilities while maintaining security through the security manager's verification and protection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9436848B2Configurator for secure feature and key manager
Publication Date: 2016.09.06 CRYPTOGRAPHY RESEARCH INC
  • US9436848B2 patent drawing
  • US9436848B2 patent drawing
  • US9436848B2 patent drawing

AI summary

A computing device receives a feature name or key name for an integrated circuit comprising a security manager core and an additional component. At least one of a) the additional component is associated with the key name or b) a feature provided by the additional component is associated with the feature name. The computing device receives a specified number of bits associated with the feature name or the key name, and maps the feature name to a feature address space or the key name to a key interface of the security manager core based at on the specified number of bits. The computing device generates at least one hardware description logic (HDL) module based on the mapping, wherein the at least one HDL module is usable to configure the security manager core for delivery of payloads associated with the feature name or the key name to the additional component.