PMIC Challenge-Response Power Domain Control for SoC Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing system-on-chip (SoC) security features are vulnerable to hacking, particularly through malicious manipulation of supply voltage, which can bypass security mechanisms and compromise safety in vehicle systems.
Innovation Solution
A power management integrated circuit (PMIC) is configured to share a key with the SoC, generating challenges and comparing responses to ensure authenticity, and in case of mismatch, applies a reset or controls power and clock domains to mitigate potential attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional power management is used without authentication, then the system is easier to operate and less complex, but the security vulnerability increases allowing malicious voltage manipulation
Solution Approach 1:
The patent implements preliminary authentication actions before power management operations. The PMIC and SoC exchange challenge-response authentication sequences during initialization, establishing trusted relationships before any power control functions are enabled. This preliminary security handshake prevents malicious actors from manipulating voltage without detection.
Solution Approach 2:
The patent introduces an intermediary authentication layer between the power management controller and the SoC. The challenge-response mechanism acts as a mediator that verifies identities before allowing power control commands to execute, adding security without requiring direct trust between components.
2Reliability
If the PMIC monitors and controls all power domains strictly, then security against voltage manipulation improves, but the system complexity and power consumption increase
Solution Approach 1:
The patent applies local quality by differentiating monitoring intensity across different power domains and operational states. During authenticated safe states, normal power management proceeds with standard monitoring. Upon authentication failure or suspicious activity detection, the PMIC intensifies monitoring specifically for security-critical domains while maintaining normal operation in non-critical domains, optimizing power consumption while enhancing security where needed.
Solution Approach 2:
The patent implements partial monitoring action by focusing intensive security monitoring only on critical power domains and authentication sequences rather than continuously monitoring all power domains at maximum intensity. This selective approach provides strong security protection where needed while reducing overall power consumption compared to universal continuous intensive monitoring.
3Reliability
If the system resets or powers down domains upon authentication failure, then security is enhanced, but the availability and productivity of the system decrease
Solution Approach 1:
The patent segments the SoC into multiple power domains with different security criticalities. Upon authentication failure, the PMIC selectively powers down or isolates only the security-critical domains that are vulnerable to the detected attack, while maintaining power supply to non-critical domains that can continue operating. This segmented approach preserves system productivity for non-security functions while enhancing security by isolating vulnerable components.
Solution Approach 2:
The patent implements preliminary anti-action by preparing and executing targeted counter-measures upon detecting authentication failures. Rather than blanket system shutdowns, the PMIC pre-configured response mechanisms that selectively apply reset or power-down only to affected security domains, preventing the malicious activity from propagating while minimizing impact on overall system availability.
Data Source
AI summary
A power management integrated circuit (PMIC) and method of operating a PMIC is described. The PMIC is configured to be coupled to a system on chip (SoC) including a number of power and clock domains. Each of the PMIC and the SoC have a shared key. The PMIC is configured to generate a challenge, output the challenge to the SoC and generate an expected-challenge-response determined from the challenge and the shared key. The PMIC is further configured to receive a challenge-response from the SoC and compare the challenge response with the expected-challenge-response. If the challenge response is different to the expected response, the PMIC may (i) apply a reset to the SoC, (ii) supply power to a subset of the SoC power domains and/or (iii) enable clocks of a subset of SoC clock domains.


