ROM Security via Address-Tied Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security circuitry in electronic devices is inadequate in combating diverse and varied software, hardware, and wireless attacks, often designed on an ad hoc basis leading to interoperability issues and increased complexity in design and testing, making them less secure.

Innovation Solution

An adaptable and flexible framework for security hardware that enables seamless interaction between different security-related circuit components using a standardized communication protocol, ensuring stable and predictable interactions, and incorporating a ROM block with encrypted data and a ROM controller for enhanced integrity checking.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security circuitry is designed on an ad hoc basis to counter specific attacks, then targeted security functionality is achieved, but interoperability between different security components deteriorates and device complexity increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoiddesign and testing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a standardized interface framework that enables different security circuitry components (such as intrusion detection circuits, tamper detection circuits, and secure element circuits) to interoperate through common protocols. This universal interface approach allows each component to maintain its specialized security function while communicating seamlessly with other security components, thereby achieving both targeted security functionality and reduced design complexity through reusability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Object-affected harmful factors

If ad hoc security circuitry is implemented for specific attack countermeasures, then attack-specific protection is provided, but interoperability issues arise between different security components

Engineering Contradiction:
Improveattack countermeasuresVSAvoidinteroperability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The patent introduces a standardized interface framework as an intermediary layer between different security circuitry components. This framework includes common protocols and communication standards that mediate interactions between components with different attack countermeasure functions. The intermediary framework ensures reliable interoperability by translating between different component-specific protocols, allowing intrusion detection circuits, tamper detection circuits, and secure element circuits to work together seamlessly without direct compatibility issues.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If hardware-based security measures are added to counter physical attacks, then protection against physical probing is improved, but device complexity and manufacturing difficulty increase

Engineering Contradiction:
Improvephysical attack protectionVSAvoidmanufacturing difficulty
Core Design Contradiction:
Object-affected harmful factorsVSEase of manufacture

Solution Approach 1:

The patent segments security functionality into separate, modular circuitry components including intrusion detection circuits, tamper detection circuits, and secure element circuits. Each module can be independently designed, tested, and manufactured using standardized processes. The modular architecture allows for specialized manufacturing techniques to be applied to each component optimally while maintaining overall system manufacturability through standardization and reduced complexity in each individual module.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240361923A1Read-Only Memory (ROM) Security
Publication Date: 2024.10.31 GOOGLE LLC
  • US20240361923A1 patent drawing
  • US20240361923A1 patent drawing
  • US20240361923A1 patent drawing

AI summary

An apparatus with an integrated circuit (IC) chip can provide protection against attacks on a read-only memory (ROM), such as a boot ROM for security circuitry. An attacker can gain control of an IC by modifying ROM contents and/or redirecting ROM reads. To combat these attacks, example implementations store encrypted ROM data in the ROM array. A ROM controller is used to cryptographically tie the address of each ROM line to the corresponding encrypted ROM datum. To access the encrypted ROM datum, cryptographic circuitry decrypts the encrypted ROM datum using a key that is generated based on the corresponding ROM address. As part of an integrity checking procedure, a digest can be computed based on the encrypted ROM data. To further thwart would-be attacks, the ROM address can be adjusted (e.g., scrambled) before the controller uses the adjusted address to read encrypted data from the ROM array.