Integrated Circuit Security Labeling and Partitioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Integrated circuits face challenges in ensuring comprehensive security and establishing a trusted platform by effectively partitioning hardware into secure and non-secure environments, as existing solutions struggle to isolate sensitive data and functions from flawed normal world software.
Innovation Solution
A method is introduced to divide integrated circuit components into non-overlapping subsets using security labels, where a computer-implemented application generates a system handoff file to configure the circuit, allowing for secure and non-secure interactions, and assigns appropriate access permissions to ensure secure data management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware components are partitioned into secure and non-secure environments, then security and trusted platform establishment is improved, but device complexity increases due to the need for multiple security labels and partitioning mechanisms
Solution Approach 1:
The patent divides hardware components into distinct secure and non-secure environments by assigning security labels to individual components. This segmentation allows sensitive data and functions to be isolated from flawed normal world software, establishing a trusted platform while maintaining manageable complexity through systematic labeling
Solution Approach 2:
The patent applies different security labels to different components based on their specific security requirements. Rather than uniformly securing the entire system, each component receives appropriate security treatment locally, optimizing security where needed while reducing unnecessary complexity in less sensitive areas
2Reliability
If comprehensive security partitioning is implemented, then protection of sensitive data is improved, but ease of operation deteriorates due to restricted access permissions between secure and non-secure worlds
Solution Approach 1:
The patent introduces a secure monitor as an intermediary that manages access permissions between secure and non-secure environments. This mediator handles the complexity of access control, allowing protected data to remain secure while enabling legitimate operations through controlled interaction channels, thus maintaining ease of operation without compromising data protection
3Manufacturing precision
If security labels are assigned to individual components, then precision of security isolation is improved, but manufacturing complexity increases due to the need for detailed component configuration and handoff file generation
Solution Approach 1:
The patent performs security label assignment and handoff file generation during the design and configuration phase, before the system is deployed. This preliminary action ensures precise security isolation is built into the system architecture from the outset, while automated tools handle the complex configuration tasks, reducing the burden on manufacturers and simplifying the production process
Data Source
AI summary
A method of dividing a set of components of an integrated circuit is disclosed. Two or more different security labels are assigned to two or more non-overlapping subsets of the set of components. A handoff file is generated based on the non-overlapping subsets and sent to the integrated circuit. The set of components of the integrated circuit is divided according to the non-overlapping subsets based on the system handoff file.


