Secure Microprocessor Memory Service Update

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electronic systems with multiple microprocessors, modifying the set of services exposed by a secure microprocessor is challenging due to non-volatile memory constraints, requiring significant resources and costs to replace the microprocessor when services need updating or modifying.

Innovation Solution

A method where a first microprocessor receives a request to modify its own memory content, accesses data and a signature generated with an asymmetric cipher algorithm from a second microprocessor, verifies the authenticity of the data, and conditionally modifies its memory to update the services exposed, without altering the non-volatile memory's set content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a new non-volatile memory storing modified software codes is provided to modify services, then the services can be updated, but the design time, resources, and cost increase significantly

Engineering Contradiction:
Improveservice update capabilityVSAvoiddesign time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments the memory system into two distinct parts: a non-volatile memory (ROM) that retains its immutable set content, and a volatile memory (RAM) that can be modified. This segmentation allows the services to be updated by modifying only the volatile memory portion, while the core non-volatile memory remains intact, avoiding the need to redesign the entire microprocessor.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a copy of the service codes from the non-volatile memory to the volatile memory, which can then be modified. The volatile memory serves as a mutable copy that can be updated without affecting the original non-volatile memory, enabling service modifications without redesigning the entire system.

Inventive Principle:
Principle #26Copying

2Adaptability or versatility

If a new non-volatile memory storing modified software codes is provided to modify services, then the services can be updated, but the manufacturing resources and cost increase significantly

Engineering Contradiction:
Improveservice update capabilityVSAvoidmanufacturing resources
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent segments the memory system into a non-volatile memory (ROM) with immutable set content and a volatile memory (RAM) that can be modified. This segmentation allows service updates to be performed by modifying only the volatile memory portion, eliminating the need to manufacture entirely new microprocessors for service updates.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic modifiability to the otherwise static non-volatile memory system by allowing the volatile memory to be updated. This creates a dynamic system where services can be modified without changing the fundamental hardware architecture, reducing manufacturing complexity.

Inventive Principle:
Principle #15Dynamics

3Ease of operation

If the content of non-volatile memory is made modifiable to update services, then service updates become easier, but the security and integrity of the memory content is compromised

Engineering Contradiction:
Improveservice modification easeVSAvoidmemory content integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the memory into a non-volatile memory (ROM) that maintains immutable set content for security, and a volatile memory (RAM) that can be modified for service updates. This segmentation preserves the integrity and security of the original memory content while enabling flexible service modifications in the volatile portion.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a volatile memory as an intermediary between the secure non-volatile memory and the service execution. This intermediary allows modifications to be made without directly altering the secure non-volatile memory content, thus maintaining security while enabling updates.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If the microprocessor is replaced with a new one to modify services, then the services can be updated, but the hardware complexity and replacement cost increase

Engineering Contradiction:
Improveservice update capabilityVSAvoidhardware replacement complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the microprocessor functionality into fixed hardware (non-volatile memory with set content) and modifiable software (volatile memory). This allows service updates to be performed by modifying only the volatile memory content, avoiding the need to replace the entire microprocessor hardware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent makes a single microprocessor design universal by enabling it to provide different service configurations through volatile memory modifications. The same hardware can serve multiple service configurations without requiring different hardware versions, reducing hardware complexity and replacement needs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11340798B2Modification of a memory of a secure microprocessor
Publication Date: 2022.05.24 STMICROELECTRONICS (ROUSSET) SAS
  • US11340798B2 patent drawing
  • US11340798B2 patent drawing
  • US11340798B2 patent drawing

AI summary

A method includes receiving, by a first microprocessor, a request of modification of a content of a first memory of the first microprocessor, the first memory being accessible only by the first microprocessor. The method includes accessing, by the first microprocessor, first data associated with the request and a signature generated from the first data with an asymmetric cipher algorithm. The first data and the signature are available in a second memory of a second microprocessor, and the first data is representative of a modification to be applied to the content of the first memory. The modification is representative of a modification of a set of services exposed by the first microprocessor. The method includes verifying, by the first microprocessor, authenticity of the first data based on the signature; and modifying the content of the first memory according to the first data, the modifying being conditioned by the verifying.