Memory Security Controller Dynamic Functional Safety Mode Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for secure access to external flash memory in microcontroller units (MCUs) face challenges in achieving a cost-efficient and processing-efficient balance between encryption, decryption, and functional safety, often resulting in overhead constraints and design cost increases.

Innovation Solution

A system with a memory security controller that operates in multiple functional safety modes, selected based on the number of pending access requests and incoming responses, allowing for dynamic switching between different cryptographic processes to optimize performance and reduce latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and decryption processes are applied to all memory access requests, then security and functional safety are improved, but processing overhead and latency increase

Engineering Contradiction:
Improvefunctional safetyVSAvoidprocessing latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically switches between different functional safety modes (first mode with full cryptographic validation, second mode with reduced validation) based on real-time system conditions such as queue depths and latency requirements, allowing optimization between security and performance

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the level of cryptographic validation applied to memory access requests based on operational parameters, applying full validation when time permits and reduced validation when latency constraints exist, thereby adapting security intensity to system state

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If multiple cryptographic validation modes are implemented, then system adaptability and performance optimization are improved, but device complexity increases

Engineering Contradiction:
Improvemode selection flexibilityVSAvoidcontroller complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The memory security controller is designed to perform multiple functions including encryption, decryption, and two different functional safety validation modes within a single device, reducing the need for separate dedicated hardware for each function

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

A mode selection controller acts as an intermediary that manages the switching between different functional safety modes based on system conditions, simplifying the control logic and reducing the complexity burden on the main memory security controller

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If full cryptographic validation is applied to all access requests, then security is improved, but throughput and processing efficiency decrease

Engineering Contradiction:
ImprovesecurityVSAvoidmemory access throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial cryptographic validation in the second functional safety mode, performing only essential security checks while omitting redundant validation steps, thereby maintaining adequate security while improving throughput for time-sensitive operations

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250147674A1Functional safety systems and methods for secure access to non-volatile memory
Publication Date: 2025.05.08 TEXAS INSTRUMENTS INC
  • US20250147674A1 patent drawing
  • US20250147674A1 patent drawing
  • US20250147674A1 patent drawing

AI summary

Various examples disclosed herein relate to controlling access to non-volatile memory devices. In an example embodiment, a device is provided. The device includes a memory security controller configured to operate in a first functional safety mode or a second functional safety mode, a security mode selection controller coupled to the memory security controller, and a memory interface controller coupled to the memory security controller and the security mode selection controller and configured to couple to a non-volatile memory. The security mode selection controller is configured to determine a number of pending access requests associated with the memory security controller, determine a number of incoming responses from the non-volatile memory to the memory security controller, and select between the first functional safety mode and the second functional safety mode based on at least one of the number of pending access requests or the number of incoming responses.