Secure Analog Link Circuit for IP GPIO Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing System-on-Chip (SoC) architectures face security vulnerabilities due to shared General Purpose Input/Output (GPIO) pads being accessed by multiple analog Intellectual Property (IP) circuits, leading to potential data eavesdropping and corruption, especially when secure and non-secure IP connections are mixed, which complicates security configurations and reduces flexibility.
Innovation Solution
Implementing a secure analog link circuit that controls signal propagation between IP circuits and GPIOs based on their security statuses, using a secure analog link component that allows or denies connection based on the security status of both the IP and GPIO, ensuring secure communication by using existing hardware components like security/protection digital controllers and GPIO controllers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple analog IP circuits are connected to the same GPIO pad through dedicated analog switches, then flexibility and adaptability are improved, but security vulnerabilities increase due to potential data eavesdropping and corruption
Solution Approach 1:
The enable signal path is segmented into multiple controlled segments, with each segment governed by a secure link circuit that independently verifies security conditions. This segmentation allows the system to maintain multiple connection paths for flexibility while inserting security checkpoints to prevent eavesdropping and corruption.
Solution Approach 2:
A secure link circuit is introduced as an intermediary component between the analog IP circuits and the GPIO pad. This intermediary monitors and controls the enable signals, verifying security conditions before allowing signal propagation, thereby protecting against security vulnerabilities without blocking legitimate flexible connections.
2Reliability
If dedicated secure GPIO configurations are implemented to prevent data eavesdropping, then security is improved, but device complexity and cost increase
Solution Approach 1:
The secure link circuit serves multiple functions: it validates security conditions, controls enable signal propagation, and interfaces with existing security controllers. By making this component multi-functional, the patent achieves enhanced security without proportionally increasing device complexity, as a single component handles multiple security-related tasks.
Solution Approach 2:
The secure link circuit automatically performs security verification and enables or disables connections based on the security status of the IP circuits and GPIO pads. This self-service capability eliminates the need for complex external security management mechanisms, reducing overall system complexity while maintaining high security standards.
3Reliability
If security verification is performed for each IP-GPIO connection, then security integrity is improved, but the number of required components and configuration overhead increase
Solution Approach 1:
Multiple security verification functions are merged into a single secure link circuit component. This unified approach allows the circuit to handle security verification for multiple IP-GPIO connections simultaneously, reducing the total number of discrete components needed while maintaining comprehensive security integrity across all connections.
Data Source
AI summary
A system includes an intellectual property circuit; a general purpose input/output circuit coupled to the intellectual property circuit via a data path; and a switch coupled to the data path. The switch is activatable via a switch enable signal propagated on a switch enable path having a first end coupled to the intellectual property circuit and a second end coupled to the general purpose input/output circuit. The system further includes a secure link circuit coupled between the intellectual property circuit and the general purpose input/output circuit along the switch enable path. The secure link circuit is sensitive to security statuses of the intellectual property circuit and the general purpose input/output circuit, the secure link circuit being configured to admit propagation of the switch enable signal on the switch enable path in response to the intellectual property circuit and the general purpose input/output circuit having identical security statuses.


