Isolated Root of Trust Component for ASIC Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Application-specific integrated circuits (ASICs) face security risks due to vulnerabilities in nonvolatile memory, which can be exploited through invasive attacks, and there is a need to enforce access control policies to maintain authenticity and reliability, especially in critical network functions.
Innovation Solution
An isolated Root of Trust (RoT) component within a System on Chip (SoC) is implemented to enforce access control policies by establishing secure communication channels, limiting access to restricted addresses, and detecting operational environments based on access rates to modify SoC operations accordingly.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If private key is placed in nonvolatile memory (EEPROM or battery-backed SRAM) for security, then cryptographic operations can be performed, but the memory becomes vulnerable to invasive attacks
Solution Approach 1:
The patent extracts the private key from vulnerable nonvolatile memory (EEPROM/SRAM) and places it exclusively in secure, tamper-resistant storage within the ASIC. This separation removes the key from environments susceptible to invasive attacks while maintaining cryptographic functionality.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the ASIC verifies device authenticity through cryptographic proof before allowing access to protected functions. This intermediary layer prevents direct access to the private key while enabling secure operations.
2Reliability
If active tamper detection/prevention circuitry is added to protect against invasive attacks, then security is improved, but the circuitry must be continually powered increasing energy consumption
Solution Approach 1:
The patent performs tamper detection and authentication checks during the boot-up and initialization phases before the ASIC becomes fully operational. By conducting security verification in advance, the system avoids the need for continuous active monitoring circuitry during normal operation, reducing energy consumption.
Solution Approach 2:
The ASIC performs self-authentication using embedded cryptographic hardware and stored credentials. This self-service approach eliminates the need for external active tamper detection systems that would require continuous power, as the device verifies its own integrity using passive, always-available security features.
3Reliability
If access control policies are enforced to maintain device authenticity, then device reliability is improved, but the complexity of access control enforcement increases
Solution Approach 1:
The patent implements a universal authentication framework where a single cryptographic verification mechanism handles multiple access control scenarios. The same authentication protocol is used for device boot, configuration access, and operational commands, simplifying the overall access control architecture despite the variety of protected functions.
4Reliability
If secure communication channels are established for protected addresses, then access security is improved, but the overhead of cryptographic verification increases processing time
Solution Approach 1:
The patent establishes secure communication channels and performs cryptographic handshakes during the initial connection phase. Once the secure channel is established, subsequent communications within that session experience reduced overhead as the cryptographic context is already validated, minimizing time loss for repeated operations.
Data Source
AI summary
This disclosure describes techniques for an isolated Root of Trust (RoT) component of a System on Chip (SoC), such as an SoC associated with a networking-related application, to: (i) enforce access to one or more protected addresses associated with the SoC using a secure communication channel, (ii) limit access to one or more restricted addresses to authorized external devices, and/or (iii) detect an operational environment within which the SoC operates based on access rates associated with special addresses associated with the SoC and modify operation of the SoC based on the detected operational environment. The RoT component may be implemented as a dedicated security subsystem with an isolated processor and memory regions that are inaccessible to the rest of the SoC.


