Secure Element Enforcing Peripheral Security Policy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing devices lack effective end-to-end security measures to protect data transmitted between device peripherals and the application processor, making them vulnerable to software and hardware attacks.

Innovation Solution

Implementing a secure element (SE) hardware processor on a physical SE component located on the communication path between peripheral components and the primary controller, which applies a security policy to messages transmitted between them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure element is introduced to enforce security policy on peripheral communications, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A secure element is introduced as an intermediary component between the application processor and peripheral devices. This secure element enforces security policies by intercepting and validating communications, ensuring that only authorized data flows between the application processor and peripherals. The secure element acts as a mediator that maintains security without requiring the application processor itself to be secure, thus improving overall system security while isolating the complexity within a dedicated security component.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security policy enforcement is implemented at the hardware level, then security strength is improved, but processing overhead and energy consumption increase

Engineering Contradiction:
Improvesecurity strengthVSAvoidenergy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security enforcement function is segmented from the main application processor and placed in a dedicated secure element. This segmentation allows the secure element to handle security policy enforcement independently, using specialized hardware circuits optimized for cryptographic operations and access control. By separating security functions from general-purpose processing, the system achieves strong security enforcement while minimizing the energy consumption impact on the main processor, as the secure element can operate efficiently using its dedicated resources.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250139255A1Secure Element Enforcing A Security Policy For Device Peripherals
Publication Date: 2025.05.01 ORACLE INT CORP
  • US20250139255A1 patent drawing
  • US20250139255A1 patent drawing
  • US20250139255A1 patent drawing

AI summary

Techniques for implementing and enforcing a security policy in a secure element are disclosed. The secure element enforces the security policy to grant and/or deny access, such as from an application processor, to configuration of the device peripheral components and access to data of the device peripheral components across one or more bus architectures, such as an I3C bus. Implementing an access control policy in a secure element allows execution of code within the isolated secure element hardware processor, preventing software attacks that may emanate from code running in the application processor. This design also benefits from hardware protections against physical attacks.