Hardware-Isolated Secure Element for Embedded System Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Devices connected to the Internet of Things are vulnerable to attacks, as firewalls can be hacked, allowing malicious users to cause damage, and software monitors can be compromised, posing risks to mission critical subsystems.

Innovation Solution

A hardware-based secure element is interposed between critical embedded components and untrusted components or networks, using a whitelist and blacklist with a secure element logic to verify firmware and operations, ensuring only trusted operations are performed, and cryptographic verification is used to protect mission critical subsystems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a firewall is used to protect devices in the Internet of Things, then network security is improved, but the firewall can be hacked by malicious users, allowing unauthorized access

Engineering Contradiction:
Improvenetwork securityVSAvoidvulnerability to hacking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the device architecture into multiple isolated components: a secure element containing critical subsystems, an electronic control unit, and untrusted components. This segmentation prevents a single point of failure (like a hacked firewall) from compromising the entire system, as the secure element remains protected behind hardware isolation boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure element acts as an intermediary between untrusted network components and critical subsystems. This intermediary enforces security policies, verifies firmware integrity, and filters operations, preventing direct access to critical functions even when firewalls are compromised.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If software monitors are used to monitor internal functions of devices, then system monitoring capability is improved, but the software monitors can be compromised by malicious users

Engineering Contradiction:
Improvesystem monitoring capabilityVSAvoidmonitor integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent replaces software-based monitoring with hardware-based monitoring through the secure element. The secure element's hardware isolation and cryptographic verification mechanisms provide monitoring capabilities that cannot be compromised by software attacks, as the monitoring logic resides in a physically separated, trusted execution environment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If a hardware-based secure element is interposed between critical components and untrusted components, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure element is designed as a multi-functional component that performs firmware verification, operation filtering, cryptographic operations, and secure communication. By consolidating these security functions into a single universal component, the patent reduces the need for multiple separate security mechanisms, thereby managing complexity while providing comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3332349B1Apparatus and method for protection of critical embedded system components via hardware-isolated secure element-based monitor
Publication Date: 2023.03.22 SAMSUNG ELECTRONICS CO LTD
  • EP3332349B1 patent drawingFigure 1
  • EP3332349B1 patent drawingFigure 2A~2B
  • EP3332349B1 patent drawingFigure 2C

AI summary

An apparatus and method of a hardware isolated secure element protecting a plurality of mission critical subsystems are provided. The method includes performing an actuation operation received across an unsecure path that modifies the state of a mission critical subsystem, performing a diagnostic operation received across the unsecure path that requests state information of the mission critical subsystem, storing information used to determine which of the diagnostic operation and the actuation operation received across the unsecure path are performed, and flashing an execution image of an electronic control unit when the execution image of the electronic control unit is received across the unsecure path.