On-Chip I/O Control via Programmable Non-Volatile Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure communication systems face challenges in managing user access rights and preventing unauthorized access, particularly in multimedia systems like set-top boxes, due to reusable passwords and complex security management that increases hardware and software complexity.

Innovation Solution

Implementing a system-on-chip individual input/output (I/O) control mechanism using programmable non-volatile memory to enable or disable access to internal chip resources, where a security processor maps control vectors to on-chip I/O buses, allowing for secure authentication and access control independent of the host processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional password-based authentication is used in secure communication systems, then user access control is implemented, but security is compromised due to password reusability and unauthorized access

Engineering Contradiction:
ImprovesecurityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the control of I/O interfaces by creating individual control bits in a control vector, where each bit corresponds to a specific I/O interface. This allows granular security control where different authentication mechanisms can be applied to different interfaces independently, preventing unauthorized access to specific segments while maintaining overall system security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the security parameter from reusable passwords to non-reusable one-time authentication tokens stored in non-volatile memory. The authentication mechanism transitions from password-based verification to challenge-response authentication using cryptographic keys, fundamentally changing how security is implemented at the I/O interface level.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive security management mechanisms are implemented to protect all I/O interfaces, then security coverage is improved, but hardware and software complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidhardware and software complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security where the security processor autonomously manages authentication and control of I/O interfaces without requiring host processor intervention. The control vector in non-volatile memory automatically stores authentication results, and the security processor independently verifies challenges and updates control bits, eliminating complex host-based security management software.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary authentication actions by pre-storing control bits in non-volatile memory that define the security state of each I/O interface. Authentication challenges are prepared in advance, and control vectors are pre-configured to enable or disable specific interfaces based on authentication outcomes, reducing runtime complexity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8844022B2Method and system to allow system-on-chip individual I/O control to be disabled and enabled by programmable non-volatile memory
Publication Date: 2014.09.23 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US8844022B2 patent drawing
  • US8844022B2 patent drawing
  • US8844022B2 patent drawing

AI summary

Certain aspects of a method and system for allowing system-on-chip individual I/O control to be disabled and enabled by programmable non-volatile memory are disclosed. Aspects of one method may include mapping at least one bit of a control vector within a security processor comprising a non-volatile memory to each of a plurality of on-chip I/O physical buses. At least one of the plurality of on-chip I/O physical buses may be enabled or disabled by modifying the mapped bit or bits of the control vector.