Secure Analog Link Circuit for IP GPIO Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing System-on-Chip (SoC) architectures face security vulnerabilities due to shared General Purpose Input/Output (GPIO) pads being accessed by multiple analog Intellectual Property (IP) circuits, leading to potential data eavesdropping and corruption, especially when secure and non-secure IP connections are mixed, which complicates security configurations and reduces flexibility.

Innovation Solution

Implementing a secure analog link circuit that controls signal propagation between IP circuits and GPIOs based on their security statuses, using a secure analog link component that allows or denies connection based on the security status of both the IP and GPIO, ensuring secure communication by using existing hardware components like security/protection digital controllers and GPIO controllers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple analog IP circuits are connected to the same GPIO pad through dedicated analog switches, then flexibility and adaptability are improved, but security vulnerabilities increase due to potential data eavesdropping and corruption

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The enable signal path is segmented into multiple controlled segments, with each segment governed by a secure link circuit that independently verifies security conditions. This segmentation allows the system to maintain multiple connection paths for flexibility while inserting security checkpoints to prevent eavesdropping and corruption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure link circuit is introduced as an intermediary component between the analog IP circuits and the GPIO pad. This intermediary monitors and controls the enable signals, verifying security conditions before allowing signal propagation, thereby protecting against security vulnerabilities without blocking legitimate flexible connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated secure GPIO configurations are implemented to prevent data eavesdropping, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure link circuit serves multiple functions: it validates security conditions, controls enable signal propagation, and interfaces with existing security controllers. By making this component multi-functional, the patent achieves enhanced security without proportionally increasing device complexity, as a single component handles multiple security-related tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The secure link circuit automatically performs security verification and enables or disables connections based on the security status of the IP circuits and GPIO pads. This self-service capability eliminates the need for complex external security management mechanisms, reducing overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If security verification is performed for each IP-GPIO connection, then security integrity is improved, but the number of required components and configuration overhead increase

Engineering Contradiction:
Improvesecurity integrityVSAvoidnumber of components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Multiple security verification functions are merged into a single secure link circuit component. This unified approach allows the circuit to handle security verification for multiple IP-GPIO connections simultaneously, reducing the total number of discrete components needed while maintaining comprehensive security integrity across all connections.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10891399B2System including intellectual property circuits communicating with a general purpose input/output pad, corresponding apparatus and method
Publication Date: 2021.01.12 STMICROELECTRONICS SRL
  • US10891399B2 patent drawing
  • US10891399B2 patent drawing
  • US10891399B2 patent drawing

AI summary

A system includes an intellectual property circuit; a general purpose input/output circuit coupled to the intellectual property circuit via a data path; and a switch coupled to the data path. The switch is activatable via a switch enable signal propagated on a switch enable path having a first end coupled to the intellectual property circuit and a second end coupled to the general purpose input/output circuit. The system further includes a secure link circuit coupled between the intellectual property circuit and the general purpose input/output circuit along the switch enable path. The secure link circuit is sensitive to security statuses of the intellectual property circuit and the general purpose input/output circuit, the secure link circuit being configured to admit propagation of the switch enable signal on the switch enable path in response to the intellectual property circuit and the general purpose input/output circuit having identical security statuses.