Reconfigurable SoC Security Architecture with Centralized Policy Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing System-on-Chip (SoC) security architectures face challenges in validating and updating security policies in-field due to ad-hoc implementations, lack of systematic processes, and high costs, which result in inadequate protection against unauthorized access to sensitive assets like cryptographic keys and user data.

Innovation Solution

A reconfigurable SoC security architecture featuring a centralized Reconfigurable Security Policy Engine (RSPE), smart security wrappers, and Design-for-Debug (DfD) infrastructure, enabling seamless and secure in-field upgrade of security policies using field-programmable gate arrays (FPGAs) to minimize energy, performance, and area overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional ad-hoc security policy implementations are used, then security policies can be implemented in SoC, but the system incurs significant costs, energy overhead, and area overhead while lacking systematic validation and update capabilities

Engineering Contradiction:
Improvesecurity policy validationVSAvoidsecurity architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security architecture into distinct modular components: a centralized Reconfigurable Security Policy Engine (RSPE) for policy validation and management, and distributed security wrappers around individual IP blocks for local enforcement. This segmentation enables systematic validation through the centralized engine while reducing overall complexity through clear separation of concerns between policy management and enforcement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer of security wrappers that mediate between the centralized RSPE and individual IP blocks. These wrappers receive policy decisions from the RSPE and enforce them locally at the IP block level, providing a systematic intermediary mechanism that enables validated security policies to be distributed and enforced throughout the SoC architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional security architectures are used, then security policies can be implemented, but updating security policies in-field is challenging and costly

Engineering Contradiction:
Improvein-field policy update capabilityVSAvoidpolicy update cost
Core Design Contradiction:
Adaptability or versatilityVSEase of manufacture

Solution Approach 1:

The patent implements a dynamic security architecture where the centralized RSPE can be reconfigured in-field to load and enforce updated security policies. The security wrappers are designed to receive and adapt to new policy configurations dynamically, enabling the system to update security policies after manufacturing without requiring physical redesign or replacement of components.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent enables parameter changes in security policies through the reconfigurable RSPE, which can load different policy configurations and parameters in-field. The security wrappers adjust their enforcement behavior based on updated policy parameters received from the RSPE, allowing cost-effective updates to security policy parameters without changing the underlying hardware architecture.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security policies are described in natural language in architecture documents, then policies can be documented, but they cannot be systematically validated or analyzed

Engineering Contradiction:
Improvepolicy analyzabilityVSAvoidpolicy representation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/documentation-based security policy representation (natural language in architecture documents) with a formal, machine-analyzable policy representation implemented in the centralized RSPE. This formal representation enables systematic validation and analysis through the RSPE's policy management capabilities, transitioning from static documentation to dynamic, verifiable policy enforcement.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If distributed security implementations are used across IP blocks, then security can be enforced locally, but energy consumption and area overhead increase significantly

Engineering Contradiction:
Improvesecurity enforcementVSAvoidsecurity overhead energy
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the complex policy validation and management functions from the distributed IP blocks and concentrates them in a centralized RSPE. The security wrappers at IP blocks retain only the essential enforcement functions, taking out the computationally intensive policy analysis and decision-making from the distributed elements and centralizing it, thereby reducing energy consumption and area overhead at the IP block level while maintaining security enforcement capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10521600B2Reconfigurable system-on-chip security architecture
Publication Date: 2019.12.31 UNIV OF FLORIDA RESEARCH FOUNDATION INC
  • US10521600B2 patent drawing
  • US10521600B2 patent drawing
  • US10521600B2 patent drawing

AI summary

Aspects of system-on-chip (SoC) security architecture that supports systematic and efficient implementation, validation, and in-field upgrade of security policies are described. In one example, an apparatus can include at least one intellectual property (IP) core, a centralized reconfigurable security policy engine (RSPE) and at least one security wrapper. The RSPE implements actionable constraint based on a security policy and at least one event frame. A security wrapper is associated with an IP core. The security wrapper is configured to communicate an event frame to the RSPE in response to an event.