OTP Life Cycle Memory Reconfiguration for Secure Diagnostics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current processing systems, such as micro-controllers, face challenges in dynamically configuring security settings, as once security configurations are programmed, they become immutable, making it difficult to analyze malfunctions or temporarily activate/deactivate security features during development or diagnostic stages without replacing the entire system.

Innovation Solution

A processing system with a hardware block and one-time programmable memory that allows life cycle data to be overwritten, enabling dynamic configuration changes through a hardware configuration module that selectively executes write requests based on conditions, such as life cycle stages and keyword verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security configuration data are programmed into non-volatile memory, then security protection is enabled and reliable, but the configuration becomes immutable and cannot be altered

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The configuration data is segmented into two parts: immutable security configuration data stored in non-volatile memory, and mutable life cycle data stored in a separate register that can be modified. This segmentation allows the security configuration to remain reliable while the life cycle data provides adaptability for different operational stages.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A configuration module acts as an intermediary between the processing unit and the configuration data. It selectively provides immutable security configuration data or modified life cycle data to configuration data clients based on access conditions, enabling dynamic configuration changes without compromising security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security features are permanently activated through configuration programming, then system security is strengthened, but the ability to diagnose and analyze malfunctions is reduced

Engineering Contradiction:
Improvesystem securityVSAvoidmalfunction analysis capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system dynamically adjusts security configuration based on life cycle data. During development and diagnostic stages, the life cycle data can be modified to temporarily deactivate security features, enabling malfunction analysis. In production stages, the immutable security configuration ensures system security is maintained.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the entire system must be replaced to change security configuration, then security protection remains absolute, but cost and complexity increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem replacement requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of replacing the entire system to change security configuration, the invention creates a copy mechanism where life cycle data can be modified in registers while the immutable security configuration data remains intact in non-volatile memory. This allows configuration changes without system replacement, reducing complexity while maintaining security protection.

Inventive Principle:
Principle #26Copying

4Adaptability or versatility

If configuration data are made writable for dynamic reconfiguration, then adaptability improves, but security protection may be compromised

Engineering Contradiction:
Improveconfiguration reconfigurabilityVSAvoidsecurity protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

Different parts of the configuration data have different writability properties. The security configuration data in non-volatile memory is read-only to maintain security protection, while the life cycle data in registers is writable to enable adaptability. This local differentiation of quality allows both security and reconfigurability to coexist.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11474752B2Processing system including one-time programmable memory with original life cycle data, related integrated circuit, device and method
Publication Date: 2022.10.18 STMICROELECTRONICS INT NV
  • US11474752B2 patent drawing
  • US11474752B2 patent drawing
  • US11474752B2 patent drawing

AI summary

A processing system comprises a processing unit, a hardware block configured to change operation as a function of life cycle data, and a one-time programmable memory storing original life cycle data. A hardware configuration module is configured to read the original life cycle data from the one-time programmable memory, to store the original life cycle data in a register, to receive a write request from the processing unit, and to selectively execute the write request to overwrite the original life cycle data with new life cycle data in the register.