LSI Secure Memory Mode Switching for Program Development
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In key-installed systems with high secrecy and confidentiality, maintaining security during program development and installation is challenging, particularly due to the need for secure memory management and encryption in LSI devices.
Innovation Solution
A method and system that utilize an LSI device with a secure memory including an unrewritable area, allowing operation mode switching from installation to development mode for program development, and employing encryption techniques to secure program development and installation, including key generation and management, while restricting raw program execution and key generation in specific modes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an LSI device with secure memory is used for program development, then security during development is improved, but the device complexity increases due to multiple operation modes and secure memory management
Solution Approach 1:
The LSI device implements dynamic operation mode switching between development mode and product operation mode. The mode switching mechanism allows the same hardware to adapt its security characteristics and functional capabilities based on the current operational context, resolving the contradiction by making security features dynamically activable rather than statically fixed
Solution Approach 2:
The secure memory is segmented into different accessible regions for different operation modes. During development mode, certain memory regions are accessible for debugging and program loading, while in product operation mode, these regions become protected. This segmentation allows the system to provide both development accessibility and production security without requiring separate physical devices
2Reliability
If raw program execution is restricted in product operation mode, then security is improved, but the ease of operation decreases for program installation and verification
Solution Approach 1:
Programs are pre-encrypted with a public key before being loaded into the LSI device. The encryption is performed in advance during the program preparation phase, so that when the program is installed in product operation mode, it can be automatically decrypted and executed without requiring the operator to manually handle sensitive cryptographic operations. This preliminary encryption action maintains security while simplifying the installation process
3Reliability
If encryption is implemented for program protection, then security is improved, but the productivity decreases due to additional encryption and decryption operations
Solution Approach 1:
The patent replaces manual cryptographic key management with an automated public key infrastructure system. The LSI device automatically performs key pair generation, program encryption, and decryption operations without requiring manual intervention. This substitution of automated cryptographic mechanisms for manual security management processes maintains high security while improving productivity by eliminating time-consuming manual operations
Data Source
AI summary
An development environment of a high security level is provided for a key-installed system. Development of a program for a system having an LSI device which includes a secure memory is performed by providing another LSI device having the same structure and setting the provided LSI device to a development mode which is different from a product operation mode. Alternatively, the provided LSI device is set to an administrator mode to perform development and encryption of a key-generation program. The LSI device is set to a key-generation mode to execute the encrypted key-generation program, thereby generating various keys.


