Multi-CPU Key Separation via Segmented Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In systems with a single security central processing unit (SCPU) on a chip, achieving an intermediate level of security is challenging as it either compromises highly secure tasks or leaves the system unsecured, and allowing user programming of SCPU functions increases risk.
Innovation Solution
Implementing a multi-security CPU approach with a first SCPU for highly secure functions and a second SCPU for lower security tasks, using a dedicated secure communications bus and secure memory to isolate sensitive operations and protect against host access, ensuring secure boot processes and key separation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single SCPU performs all security functions, then device complexity is reduced, but security reliability deteriorates due to inability to isolate sensitive operations
Solution Approach 1:
The patent divides the single SCPU into multiple SCPUs (first SCPU for highly secure functions, second SCPU for lower security tasks). This segmentation isolates sensitive operations from less secure functions, preventing contamination while maintaining overall system security. Each SCPU operates at its own security level with dedicated memory and communication channels.
Solution Approach 2:
The patent introduces a secure communication bus as an intermediary between SCPUs and the host processor. This intermediary channel allows controlled information exchange while maintaining security boundaries, enabling the host to access decrypted content without accessing encryption keys or sensitive operations.
2Adaptability or versatility
If user programming of SCPU functions is allowed, then adaptability improves, but security reliability worsens due to increased risk
Solution Approach 1:
The patent applies different quality levels to different SCPUs based on their security requirements. The first SCPU operates at a higher security level with restricted programming capabilities, while the second SCPU operates at a lower security level with greater programming flexibility. This local differentiation allows user programming where appropriate without compromising overall system security.
3Adaptability or versatility
If intermediate security level is implemented, then security coverage improves, but system stability worsens due to compromised highly secure tasks
Solution Approach 1:
The patent segments security functions across multiple SCPUs with distinct security levels. The first SCPU maintains stable, highly secure operations for critical functions, while the second SCPU handles intermediate security tasks. This segmentation prevents instability in high-security operations from affecting critical functions.
Data Source
AI summary
A computing system, comprising includes a first central processing unit (CPU) and a second CPU coupled with the first CPU and with a host processor. The second CPU and the host processor may both request the first CPU to generate keys that have access rights to regions of memory to access specific data. The first CPU may be configured to, in response to a request from the second CPU, generate a unique key with a unique access right to a region of memory, the unique key usable only by the second CPU, not the host processor.


