Isolated Root of Trust Component for ASIC Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Application-specific integrated circuits (ASICs) face security risks due to vulnerabilities in nonvolatile memory, which can be exploited through invasive attacks, and there is a need to enforce access control policies to maintain authenticity and reliability, especially in critical network functions.

Innovation Solution

An isolated Root of Trust (RoT) component within a System on Chip (SoC) is implemented to enforce access control policies by establishing secure communication channels, limiting access to restricted addresses, and detecting operational environments based on access rates to modify SoC operations accordingly.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If private key is placed in nonvolatile memory (EEPROM or battery-backed SRAM) for security, then cryptographic operations can be performed, but the memory becomes vulnerable to invasive attacks

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to invasive attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the private key from vulnerable nonvolatile memory (EEPROM/SRAM) and places it exclusively in secure, tamper-resistant storage within the ASIC. This separation removes the key from environments susceptible to invasive attacks while maintaining cryptographic functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary authentication mechanism where the ASIC verifies device authenticity through cryptographic proof before allowing access to protected functions. This intermediary layer prevents direct access to the private key while enabling secure operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If active tamper detection/prevention circuitry is added to protect against invasive attacks, then security is improved, but the circuitry must be continually powered increasing energy consumption

Engineering Contradiction:
Improveprotection against attacksVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs tamper detection and authentication checks during the boot-up and initialization phases before the ASIC becomes fully operational. By conducting security verification in advance, the system avoids the need for continuous active monitoring circuitry during normal operation, reducing energy consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The ASIC performs self-authentication using embedded cryptographic hardware and stored credentials. This self-service approach eliminates the need for external active tamper detection systems that would require continuous power, as the device verifies its own integrity using passive, always-available security features.

Inventive Principle:
Principle #25Self-service

3Reliability

If access control policies are enforced to maintain device authenticity, then device reliability is improved, but the complexity of access control enforcement increases

Engineering Contradiction:
Improvedevice authenticityVSAvoidaccess control enforcement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication framework where a single cryptographic verification mechanism handles multiple access control scenarios. The same authentication protocol is used for device boot, configuration access, and operational commands, simplifying the overall access control architecture despite the variety of protected functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If secure communication channels are established for protected addresses, then access security is improved, but the overhead of cryptographic verification increases processing time

Engineering Contradiction:
Improveaccess securityVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent establishes secure communication channels and performs cryptographic handshakes during the initial connection phase. Once the secure channel is established, subsequent communications within that session experience reduced overhead as the cryptographic context is already validated, minimizing time loss for repeated operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250190596A1Techniques for enforcing access control policies for application-specific integrated circuits (ASICS)
Publication Date: 2025.06.12 CISCO SYSTEMS INC
  • US20250190596A1 patent drawing
  • US20250190596A1 patent drawing
  • US20250190596A1 patent drawing

AI summary

This disclosure describes techniques for an isolated Root of Trust (RoT) component of a System on Chip (SoC), such as an SoC associated with a networking-related application, to: (i) enforce access to one or more protected addresses associated with the SoC using a secure communication channel, (ii) limit access to one or more restricted addresses to authorized external devices, and/or (iii) detect an operational environment within which the SoC operates based on access rates associated with special addresses associated with the SoC and modify operation of the SoC based on the detected operational environment. The RoT component may be implemented as a dedicated security subsystem with an isolated processor and memory regions that are inaccessible to the rest of the SoC.