Secure Computing Module With Switchable Crypto Redundancy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing integrated circuits in vehicles face challenges in efficiently balancing functional safety and security requirements, particularly in handling secure boot and secure communication, while maintaining performance and reducing complexity and cost.
Innovation Solution
An integrated circuit with a secure computing module featuring dual cryptographic data handling systems that can be selectively switched between modes, providing hardware redundancy for safety-related data and independent operation for non-safety-related data, utilizing time-diverse error detection and dual core lockstep (DCLS) for redundancy, and incorporating a safety-performance secure switch (SPSS) for dynamic mode switching.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware redundancy is implemented for safety-related data processing, then reliability is improved, but device complexity increases
Solution Approach 1:
The cryptographic data handling system is segmented into two independent but identical copies (first and second cryptographic units with corresponding data transfer units). Each copy can operate independently to process safety-related data, providing hardware redundancy without requiring a completely separate redundant system. This segmentation allows the reliability improvement while containing complexity within modular units.
Solution Approach 2:
The first and second cryptographic data handling systems are designed to be universal and interchangeable, each capable of performing the same cryptographic functions. This multi-functionality allows either system to take over if the other fails, providing reliability through redundancy while using identical standardized components rather than complex specialized hardware for each redundant path.
2Productivity
If cryptographic data handling systems are operated in parallel for high throughput, then productivity is improved, but device complexity increases
Solution Approach 1:
The system dynamically switches between operational modes based on data type: for non-safety-related data, the first cryptographic unit operates independently at high throughput; for safety-related data, both units are activated in parallel with coordinated operation. This dynamic adaptation allows high productivity for general processing while maintaining safety requirements only when necessary, avoiding permanent complex architecture.
Solution Approach 2:
The safety-critical redundant processing capability is extracted as a separate, optional mode rather than being permanently active. The selector circuitry allows the system to take out the redundancy mechanism and engage it only when safety-related data requires processing, thereby achieving high throughput for non-safety data while preserving the ability to provide reliability when needed.
3Ease of operation
If independent operation of cryptographic units is used for non-safety data, then ease of operation is improved, but reliability deteriorates
Solution Approach 1:
The system dynamically adapts its operational mode based on the safety requirements of the data being processed. For non-safety-related data, independent operation provides simplicity; for safety-related data, coordinated parallel operation provides reliability. This dynamic switching resolves the contradiction by applying the appropriate operational mode to each data type rather than using a fixed mode for all operations.
Solution Approach 2:
Different operational qualities are applied to different data streams: independent operation (simpler mode) for non-safety data and coordinated redundant operation (stricter mode) for safety-related data. This local differentiation of operational quality allows the system to optimize for ease of operation where safety is not concerned while ensuring reliability where it is required.
4Reliability
If coordinated parallel operation of cryptographic units is used for safety data, then reliability is improved, but productivity decreases
Solution Approach 1:
The coordinated parallel operation mode is extracted as a specialized capability activated only when safety-related data requires processing. For non-safety data, the system uses independent operation at full throughput. This extraction approach ensures that the reliability-enhancing coordinated mode is applied only where necessary, minimizing its impact on overall productivity while maintaining safety requirements.
Solution Approach 2:
The system dynamically switches between independent operation (high throughput) and coordinated parallel operation (high reliability) based on the safety requirements of the current data stream. This dynamic mode switching allows the system to achieve high productivity for the majority of non-safety data while ensuring safety-critical data receives the enhanced reliability treatment, balancing overall system performance.
Data Source
AI summary
An integrated circuit includes a safety processor and a secure computing module including a secure processor, first and second cryptographic units for encrypting and decrypting data, and first and second data transfer units for transferring data between a memory and the first and second cryptographic units respectively. The first cryptographic unit and the first data transfer unit provide a first cryptographic data handling system and the second cryptographic unit and the second data transfer unit provide a second cryptographic data handling system. The secure computing module includes selector circuitry for selectively coupling and uncoupling the first and second cryptographic units in response to control signals from a switch. In a first mode, the first and second cryptographic data handling systems are uncoupled and operable independently of each other. In a second mode, the first and second cryptographic data handling system are coupled and operable together to provide hardware redundancy.


