OTP Life Cycle Memory Reconfiguration for Secure Diagnostics
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current processing systems, such as micro-controllers, face challenges in dynamically configuring security settings, as once security configurations are programmed, they become immutable, making it difficult to analyze malfunctions or temporarily activate/deactivate security features during development or diagnostic stages without replacing the entire system.
Innovation Solution
A processing system with a hardware block and one-time programmable memory that allows life cycle data to be overwritten, enabling dynamic configuration changes through a hardware configuration module that selectively executes write requests based on conditions, such as life cycle stages and keyword verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security configuration data are programmed into non-volatile memory, then security protection is enabled and reliable, but the configuration becomes immutable and cannot be altered
Solution Approach 1:
The configuration data is segmented into two parts: immutable security configuration data stored in non-volatile memory, and mutable life cycle data stored in a separate register that can be modified. This segmentation allows the security configuration to remain reliable while the life cycle data provides adaptability for different operational stages.
Solution Approach 2:
A configuration module acts as an intermediary between the processing unit and the configuration data. It selectively provides immutable security configuration data or modified life cycle data to configuration data clients based on access conditions, enabling dynamic configuration changes without compromising security protection.
2Reliability
If security features are permanently activated through configuration programming, then system security is strengthened, but the ability to diagnose and analyze malfunctions is reduced
Solution Approach 1:
The system dynamically adjusts security configuration based on life cycle data. During development and diagnostic stages, the life cycle data can be modified to temporarily deactivate security features, enabling malfunction analysis. In production stages, the immutable security configuration ensures system security is maintained.
3Reliability
If the entire system must be replaced to change security configuration, then security protection remains absolute, but cost and complexity increase
Solution Approach 1:
Instead of replacing the entire system to change security configuration, the invention creates a copy mechanism where life cycle data can be modified in registers while the immutable security configuration data remains intact in non-volatile memory. This allows configuration changes without system replacement, reducing complexity while maintaining security protection.
4Adaptability or versatility
If configuration data are made writable for dynamic reconfiguration, then adaptability improves, but security protection may be compromised
Solution Approach 1:
Different parts of the configuration data have different writability properties. The security configuration data in non-volatile memory is read-only to maintain security protection, while the life cycle data in registers is writable to enable adaptability. This local differentiation of quality allows both security and reconfigurability to coexist.
Data Source
AI summary
A processing system comprises a processing unit, a hardware block configured to change operation as a function of life cycle data, and a one-time programmable memory storing original life cycle data. A hardware configuration module is configured to read the original life cycle data from the one-time programmable memory, to store the original life cycle data in a register, to receive a write request from the processing unit, and to selectively execute the write request to overwrite the original life cycle data with new life cycle data in the register.


