Secure Data Processing Circuit with Check Word Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data processing circuit arrangements fail to protect data from manipulation and errors throughout the entire processing path, particularly after data is loaded from external memory into the arithmetic and logic unit, leaving it vulnerable to attacks and errors.
Innovation Solution
A circuit arrangement with an internal memory providing a protected data record containing instruction words and check words, where a checking apparatus allocates and compares check words to ensure data integrity, generating an alarm if changes occur, and a method for secure data processing that allocates and compares check words to detect any alterations during execution.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If data are stored in external memory and loaded into internal memory for processing, then data processing speed is improved, but data security deteriorates because data become vulnerable to manipulation after loading
Solution Approach 1:
The invention applies preliminary action by generating check words from the instruction words before the instruction words are executed by the arithmetic and logic unit. These check words are stored in association with the instruction words in internal memory, so that when the instruction words are later accessed for processing, the check words are already available for immediate integrity verification. This prevents the security vulnerability that would otherwise exist during the processing phase.
Solution Approach 2:
The invention implements feedback by continuously monitoring the integrity of instruction words during processing. The checking apparatus generates check words from the instruction words being processed and compares them with the pre-stored check words. If any discrepancy is detected, the system can immediately respond by initiating error correction or security protocols, thus maintaining data security throughout the processing operation rather than only at static points.
2Reliability
If protective measures are applied to external memory with cryptographic units and error-correcting codes, then data protection is improved, but the protected area is restricted and does not extend to the arithmetic and logic unit
Solution Approach 1:
The invention applies universality by making the check word generation and verification mechanism applicable to any instruction words in internal memory that are accessed by the arithmetic and logic unit. Unlike previous solutions that protected only specific portions of the system, this approach can be universally applied to all data processing operations in the CPU, making the protection scope as versatile and comprehensive as the data processing itself.
Solution Approach 2:
The invention uses segmentation by dividing the protection mechanism into independent check word generation and verification units that can be applied to individual instruction words or groups of instruction words. This allows flexible segmentation of the protected area within internal memory, enabling protection of specific critical routines or data while leaving other areas unprotected, thus achieving both comprehensive and selective protection capabilities.
3Reliability
If check words are allocated and compared throughout the data processing path, then data integrity is improved, but device complexity increases
Solution Approach 1:
The invention applies self-service by enabling the system to automatically generate and verify check words without requiring external intervention or complex external monitoring systems. The checking apparatus within the system generates check words from the instruction words themselves and performs self-verification by comparing generated check words with stored check words. This self-contained approach maintains data integrity while avoiding the complexity of external protection mechanisms.
Solution Approach 2:
The invention uses merging by integrating the check word generation and verification functions directly into the existing data processing path between internal memory and the arithmetic and logic unit. Rather than adding separate complex external monitoring systems, the protection mechanism is merged with the existing data flow, using the same data paths and timing signals already present in the system, thus minimizing additional circuit complexity.
Data Source
AI summary
Circuit arrangement for secure data processing for program data with a protected data record. An internal memory provides a protected data record having instruction words and a first check word associated with the instruction words. An arithmetic and logic unit has an input coupled to the internal memory and outputs the first check word from the applied protected data record. A checking apparatus has an input coupled between the internal memory and the arithmetic and logic unit, and allocates a second check word to the instruction words in the protected data record. A comparison apparatus has respective inputs coupled to the checking apparatus and the arithmetic and logic unit, and compares the first check word with the second check word, and outputs an alarm signal when the first check word does not match the second check word.


