Multi-Core Tamper-Resistant Microprocessor with Centralized Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current tamper-resistant processors in multi-processor configurations lack an effective encryption function that can utilize multiple encryption keys across multiple processor cores on a single package, compromising the security and integrity of program execution codes and data in multi-task environments.

Innovation Solution

A tamper-resistant microprocessor package with an internal bus interface unit and an encryption/decryption processing unit that stores keys corresponding to programs, allowing for secure encryption and decryption of memory data across multiple processor cores on a single package, ensuring secure execution and data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a common hardware encryption/decryption processing unit is shared across multiple processor cores, then device complexity is reduced, but security is compromised because multiple keys cannot be simultaneously managed for different programs

Engineering Contradiction:
Improveencryption processing hardwareVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The key management functionality is segmented into separate key tables for each processor core (ECU), allowing each core to have its own dedicated encryption keys while sharing the physical encryption/decryption hardware unit. This segmentation enables simultaneous secure operation of multiple programs on different cores without key conflicts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The bus interface unit acts as an intermediary between the processor cores and the shared encryption/decryption processing unit. It manages key selection and coordination, ensuring that the appropriate keys are applied for each core's operations while maintaining security isolation between different programs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple encryption keys are managed for different programs on multiple processor cores, then security is improved, but device complexity increases due to the need for separate key management structures

Engineering Contradiction:
ImprovesecurityVSAvoidkey management structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The bus interface unit is designed as a universal component that serves multiple functions: it manages key tables for multiple processor cores, handles both encryption and decryption operations, and coordinates access to the shared encryption/decryption hardware. This multi-functionality reduces the need for separate dedicated structures for each core.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Speed

If an internal bus is used to connect processor cores within a single package, then processing speed is improved, but vulnerability to illegal alteration increases compared to external package connections

Engineering Contradiction:
Improveprocessing speedVSAvoidvulnerability to illegal alteration
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The encryption function is integrated into the bus interface unit operating on the internal bus, providing preliminary security protection for data before it is processed by the processor cores. This ensures that even though the internal bus is physically accessible, the data remains encrypted and protected from illegal alteration during transmission between the bus interface and processor cores.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS7590869B2On-chip multi-core type tamper resistant microprocessor
Publication Date: 2009.09.15 KK TOSHIBA
  • US7590869B2 patent drawing
  • US7590869B2 patent drawing
  • US7590869B2 patent drawing

AI summary

The on-chip multi-core type tamper resistant processor has a feature that, on the microprocessor package which has a plurality of instruction execution cores on an identical package and an ciphering processing function that can use a plurality of ciphering keys in correspondence to programs under a multi-task program execution environment, a key table for storing ciphering keys and the ciphering processing function are concentrated on a single location on the package, such that it is possible to provide a tamper resistant microprocessor in the multi-processor configuration that can realize the improved processing performance by hardware of a given size compared with the case of providing the key table and the ciphering processing function distributedly.