Integrated Circuit Security Manager for Privilege Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing integrated circuits lack an efficient method to manage and revoke privileges assigned to different entities throughout their lifecycle, leading to potential security vulnerabilities and access control issues as entities transfer ownership and responsibilities.

Innovation Solution

Incorporating a security manager within the integrated circuit that utilizes a memory, such as a one-time programmable (OTP) memory, to assign and revoke privileges for various entities, allowing for secure management of access to functionality and operations through delegation and revocation signals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security manager is incorporated to manage and revoke privileges for different entities, then security control and access management are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity controlVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security manager component is introduced as an intermediary between entities and the integrated circuit functionality. This security manager maintains a registry of authorized entities and their privileges, and intercepts access requests to verify authorization. By placing this intermediary layer, the patent achieves improved security control without requiring fundamental redesign of the entire circuit architecture, thus managing the complexity increase.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security management functionality is segmented into distinct components: a security manager unit, a registry structure for storing entity information, and privilege verification logic. This segmentation allows the security system to be implemented as modular additions rather than monolithic changes, making the complexity more manageable and the system easier to maintain.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If privilege management functionality is added to manage entity access rights, then access control capability is improved, but manufacturing complexity increases

Engineering Contradiction:
Improveaccess control capabilityVSAvoidmanufacturing complexity
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements preliminary action by pre-configuring the security manager and registry structure during the integrated circuit manufacturing process. Entity identifiers and initial privilege sets are programmed into the registry before the circuit is deployed. This preliminary configuration simplifies subsequent manufacturing steps and reduces the need for complex post-manufacturing setup procedures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security manager is designed as a universal component that can manage multiple entities and various types of privileges through a single standardized interface. Rather than creating separate access control mechanisms for different entities or functions, this multi-functional security manager handles all access control requirements, thereby reducing overall manufacturing complexity despite the added capability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If OTP memory is used to store privilege information, then security and integrity are improved, but flexibility in updating privileges is reduced

Engineering Contradiction:
ImproveintegrityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by using OTP memory specifically for storing critical, immutable data such as entity identifiers and core privilege definitions that require high integrity. Meanwhile, other parts of the system that require frequent updates, such as access logs or temporary authorization states, are stored in more flexible memory types. This selective application of storage technologies optimizes both security and flexibility.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11789625B2Managing privileges of different entities for an integrated circuit
Publication Date: 2023.10.17 CRYPTOGRAPHY RESEARCH INC
  • US11789625B2 patent drawing
  • US11789625B2 patent drawing
  • US11789625B2 patent drawing

AI summary

A request associated with one or more privileges assigned to a first entity may be received. Each of the one or more privileges may correspond to an operation of an integrated circuit. Information corresponding to the first entity and stored in a memory that is associated with the integrated circuit may be identified. Furthermore, the memory may be programmed to modify the information stored in the memory that is associated with the integrated circuit in response to the request associated with the one or more privileges assigned to the first entity.