Secure Computing Module With Switchable Crypto Redundancy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing integrated circuits in vehicles face challenges in efficiently balancing functional safety and security requirements, particularly in handling secure boot and secure communication, while maintaining performance and reducing complexity and cost.

Innovation Solution

An integrated circuit with a secure computing module featuring dual cryptographic data handling systems that can be selectively switched between modes, providing hardware redundancy for safety-related data and independent operation for non-safety-related data, utilizing time-diverse error detection and dual core lockstep (DCLS) for redundancy, and incorporating a safety-performance secure switch (SPSS) for dynamic mode switching.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware redundancy is implemented for safety-related data processing, then reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesafety assuranceVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The cryptographic data handling system is segmented into two independent but identical copies (first and second cryptographic units with corresponding data transfer units). Each copy can operate independently to process safety-related data, providing hardware redundancy without requiring a completely separate redundant system. This segmentation allows the reliability improvement while containing complexity within modular units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The first and second cryptographic data handling systems are designed to be universal and interchangeable, each capable of performing the same cryptographic functions. This multi-functionality allows either system to take over if the other fails, providing reliability through redundancy while using identical standardized components rather than complex specialized hardware for each redundant path.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Productivity

If cryptographic data handling systems are operated in parallel for high throughput, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvedata processing throughputVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system dynamically switches between operational modes based on data type: for non-safety-related data, the first cryptographic unit operates independently at high throughput; for safety-related data, both units are activated in parallel with coordinated operation. This dynamic adaptation allows high productivity for general processing while maintaining safety requirements only when necessary, avoiding permanent complex architecture.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The safety-critical redundant processing capability is extracted as a separate, optional mode rather than being permanently active. The selector circuitry allows the system to take out the redundancy mechanism and engage it only when safety-related data requires processing, thereby achieving high throughput for non-safety data while preserving the ability to provide reliability when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If independent operation of cryptographic units is used for non-safety data, then ease of operation is improved, but reliability deteriorates

Engineering Contradiction:
Improveoperational simplicityVSAvoidsafety assurance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system dynamically adapts its operational mode based on the safety requirements of the data being processed. For non-safety-related data, independent operation provides simplicity; for safety-related data, coordinated parallel operation provides reliability. This dynamic switching resolves the contradiction by applying the appropriate operational mode to each data type rather than using a fixed mode for all operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Different operational qualities are applied to different data streams: independent operation (simpler mode) for non-safety data and coordinated redundant operation (stricter mode) for safety-related data. This local differentiation of operational quality allows the system to optimize for ease of operation where safety is not concerned while ensuring reliability where it is required.

Inventive Principle:
Principle #3Local quality

4Reliability

If coordinated parallel operation of cryptographic units is used for safety data, then reliability is improved, but productivity decreases

Engineering Contradiction:
Improvesafety assuranceVSAvoiddata processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The coordinated parallel operation mode is extracted as a specialized capability activated only when safety-related data requires processing. For non-safety data, the system uses independent operation at full throughput. This extraction approach ensures that the reliability-enhancing coordinated mode is applied only where necessary, minimizing its impact on overall productivity while maintaining safety requirements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system dynamically switches between independent operation (high throughput) and coordinated parallel operation (high reliability) based on the safety requirements of the current data stream. This dynamic mode switching allows the system to achieve high productivity for the majority of non-safety data while ensuring safety-critical data receives the enhanced reliability treatment, balancing overall system performance.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12475261B2Integrated circuit
Publication Date: 2025.11.18 RENESAS ELECTRONICS CORP
  • US12475261B2 patent drawing
  • US12475261B2 patent drawing
  • US12475261B2 patent drawing

AI summary

An integrated circuit includes a safety processor and a secure computing module including a secure processor, first and second cryptographic units for encrypting and decrypting data, and first and second data transfer units for transferring data between a memory and the first and second cryptographic units respectively. The first cryptographic unit and the first data transfer unit provide a first cryptographic data handling system and the second cryptographic unit and the second data transfer unit provide a second cryptographic data handling system. The secure computing module includes selector circuitry for selectively coupling and uncoupling the first and second cryptographic units in response to control signals from a switch. In a first mode, the first and second cryptographic data handling systems are uncoupled and operable independently of each other. In a second mode, the first and second cryptographic data handling system are coupled and operable together to provide hardware redundancy.