Reconfigurable SoC Security Architecture with Centralized Policy Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing System-on-Chip (SoC) security architectures face challenges in validating and updating security policies in-field due to ad-hoc implementations, lack of systematic processes, and high costs, which result in inadequate protection against unauthorized access to sensitive assets like cryptographic keys and user data.
Innovation Solution
A reconfigurable SoC security architecture featuring a centralized Reconfigurable Security Policy Engine (RSPE), smart security wrappers, and Design-for-Debug (DfD) infrastructure, enabling seamless and secure in-field upgrade of security policies using field-programmable gate arrays (FPGAs) to minimize energy, performance, and area overhead.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional ad-hoc security policy implementations are used, then security policies can be implemented in SoC, but the system incurs significant costs, energy overhead, and area overhead while lacking systematic validation and update capabilities
Solution Approach 1:
The patent segments the security architecture into distinct modular components: a centralized Reconfigurable Security Policy Engine (RSPE) for policy validation and management, and distributed security wrappers around individual IP blocks for local enforcement. This segmentation enables systematic validation through the centralized engine while reducing overall complexity through clear separation of concerns between policy management and enforcement.
Solution Approach 2:
The patent introduces an intermediary layer of security wrappers that mediate between the centralized RSPE and individual IP blocks. These wrappers receive policy decisions from the RSPE and enforce them locally at the IP block level, providing a systematic intermediary mechanism that enables validated security policies to be distributed and enforced throughout the SoC architecture.
2Adaptability or versatility
If traditional security architectures are used, then security policies can be implemented, but updating security policies in-field is challenging and costly
Solution Approach 1:
The patent implements a dynamic security architecture where the centralized RSPE can be reconfigured in-field to load and enforce updated security policies. The security wrappers are designed to receive and adapt to new policy configurations dynamically, enabling the system to update security policies after manufacturing without requiring physical redesign or replacement of components.
Solution Approach 2:
The patent enables parameter changes in security policies through the reconfigurable RSPE, which can load different policy configurations and parameters in-field. The security wrappers adjust their enforcement behavior based on updated policy parameters received from the RSPE, allowing cost-effective updates to security policy parameters without changing the underlying hardware architecture.
3Reliability
If security policies are described in natural language in architecture documents, then policies can be documented, but they cannot be systematically validated or analyzed
Solution Approach 1:
The patent replaces the mechanical/documentation-based security policy representation (natural language in architecture documents) with a formal, machine-analyzable policy representation implemented in the centralized RSPE. This formal representation enables systematic validation and analysis through the RSPE's policy management capabilities, transitioning from static documentation to dynamic, verifiable policy enforcement.
4Reliability
If distributed security implementations are used across IP blocks, then security can be enforced locally, but energy consumption and area overhead increase significantly
Solution Approach 1:
The patent extracts the complex policy validation and management functions from the distributed IP blocks and concentrates them in a centralized RSPE. The security wrappers at IP blocks retain only the essential enforcement functions, taking out the computationally intensive policy analysis and decision-making from the distributed elements and centralizing it, thereby reducing energy consumption and area overhead at the IP block level while maintaining security enforcement capability.
Data Source
AI summary
Aspects of system-on-chip (SoC) security architecture that supports systematic and efficient implementation, validation, and in-field upgrade of security policies are described. In one example, an apparatus can include at least one intellectual property (IP) core, a centralized reconfigurable security policy engine (RSPE) and at least one security wrapper. The RSPE implements actionable constraint based on a security policy and at least one event frame. A security wrapper is associated with an IP core. The security wrapper is configured to communicate an event frame to the RSPE in response to an event.


