RISC-V Processor Hardware Security Module for IoT Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software-based solutions for protecting networked devices from intrusion are costly, time-consuming, and inefficient, especially in large networks, and can be vulnerable to attacks, with software-based 'watchdog' mechanisms being susceptible to malware and firmware reflashing.

Innovation Solution

A hardware-based solution using a reduced instruction set computer with a secure hardware-implemented module that verifies signed PKI messages to switch between operational and safe states, maintaining communication with a control facility while preventing software execution in the safe state, utilizing an open-source RISC-V instruction set architecture to ensure security and compatibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based detection or prevention solutions are used to protect networked devices, then security protection is provided, but the solution becomes expensive and time-consuming to configure and manage in large networks

Engineering Contradiction:
Improvesecurity protectionVSAvoidconfiguration and management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces software-based security mechanisms with a hardware-based security module integrated into the processor. This hardware module autonomously monitors system state and enforces security policies, eliminating the need for complex software configuration and management while providing reliable security protection.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The hardware security module operates autonomously to monitor system state, detect anomalies, and enforce security policies without requiring external software intervention. This self-service capability reduces configuration and management overhead while maintaining security protection.

Inventive Principle:
Principle #25Self-service

2Reliability

If software-defined networking is used to disconnect suspect machines from the network, then security is maintained, but the process becomes time-consuming and inefficient

Engineering Contradiction:
Improvesecurity maintenanceVSAvoidresponse time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces software-based network disconnection mechanisms with hardware-level security module actions. The hardware module can immediately isolate compromised components or terminate malicious processes at the hardware level, dramatically reducing response time while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The hardware security module continuously monitors system state in advance, detecting security threats before they can cause significant damage. This preliminary detection enables immediate response actions, reducing the time loss associated with security incidents.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If software-based watchdog or override mechanisms are implemented, then system monitoring is provided, but these mechanisms become vulnerable to attacks and firmware reflashing

Engineering Contradiction:
Improvesystem monitoringVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces software-based watchdog mechanisms with a dedicated hardware security module. This hardware implementation is inherently more resistant to attacks and firmware reflashing, as it operates at a lower level with protected access, while maintaining system monitoring capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent separates the security monitoring function into a distinct hardware module independent of the main processor and software system. This segmentation isolates the watchdog function from potential software attacks and firmware modification, enhancing security while maintaining monitoring reliability.

Inventive Principle:
Principle #1Segmentation

4Reliability

If closed-source processor architecture is used, then proprietary security features may be implemented, but hidden security flaws cannot be detected

Engineering Contradiction:
Improveproprietary security featuresVSAvoidsecurity flaw detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of relying on proprietary closed-source architecture, the patent adopts an open-source instruction set architecture for the processor while implementing security features in hardened hardware. This inversion allows independent security auditing of the software layer while maintaining secure hardware enforcement, enabling detection of hidden security flaws.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11177934B2Open processor for operation technology and internet of things
Publication Date: 2021.11.16 NEC CORP
  • US11177934B2 patent drawing
  • US11177934B2 patent drawing

AI summary

A computing device comprises a network element configured for receiving messages sent over a network from a control facility, a reduced instruction set computer processing circuitry comprising a central processing unit (CPU) and a secure hardware-implemented module adapted to verify that a signed PKI message is encoded in the received messages at a plurality of sequential intervals and to either switch the CPU from an operational state to a safe state, or prevent switching of the CPU from the safe state to the operational state, when a receipt of a signed PKI message is not verified in one of the sequential intervals. In the operational state, the CPU accesses a memory address space in the processing circuitry for executing software-based commands. In the safe state the CPU is prevented from executing the software-based commands while access to the memory address space is retained.