Monolithic IC Security Code Validation for Data Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing systems lack effective mechanisms to prevent unauthorized changes to executable code and data within integrated circuits, particularly during and after manufacturing, which compromises data integrity and security.

Innovation Solution

A data processing apparatus comprising a monolithic integrated circuit with a data processor, non-volatile memory for storing security codes, and interfaces, where processing is dependent on validated security codes to ensure secure communication and prevent unauthorized access, utilizing cryptographic measures like digital signatures and one-time programmable memories to secure the system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data processing systems use standard interfaces for communication, then ease of operation and adaptability are improved, but security and data integrity are worsened due to unauthorized access risks

Engineering Contradiction:
Improveease of communicationVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces security codes as an intermediary mechanism between the data processor and external interfaces. These security codes act as mediators that validate all data transactions, allowing standard interfaces to remain open for communication while ensuring that only authorized data processing occurs. The security code verifies the integrity of executable code and data before processing, preventing unauthorized access without blocking legitimate communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security codes are stored in non-volatile memory within the integrated circuit, then data security is improved, but device complexity increases due to additional memory components

Engineering Contradiction:
Improvesecurity code storageVSAvoidintegrated circuit structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security code storage function with the existing non-volatile memory structure of the integrated circuit. Rather than adding completely separate security hardware, the security codes are stored in the same non-volatile memory that already exists for storing executable code and data. This integration approach provides security functionality while minimizing additional device complexity, as the memory infrastructure is shared between security and operational functions.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If security validation is performed for all data processing operations, then data integrity is improved, but processing speed and productivity are worsened due to validation overhead

Engineering Contradiction:
Improvedata integrityVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary validation by checking security codes and validating executable code before they are loaded into the data processor for execution. The security code validates the integrity of code and data in advance, before they enter the critical processing path. This preliminary action ensures data integrity while minimizing impact on processing speed, as the validation occurs before rather than during the main processing operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8347111B2Data processing apparatus
Publication Date: 2013.01.01 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8347111B2 patent drawing
  • US8347111B2 patent drawing
  • US8347111B2 patent drawing

AI summary

A data processing apparatus comprises a monolithic integrated circuit having a data processor, a non-volatile memory storing at least one security code, and at least one interface at the boundary of the integrated circuit via which communication with the data processor can occur. Processing by the data processor of data received at the at least one interface is controlled by the at least one security code.