Secure Mailbox Filter for Multi-Master SoC Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Systems on Chips (SoCs) with multi-master Mailboxes lack secure identification of emitters, allowing unauthorized access to the Secure Element, which compromises the security of sensitive data and cryptographic operations.
Innovation Solution
Implementing a Secure Mailbox with a filter that uses hardware identifiers and cryptographic keys to authenticate and authorize access, ensuring only authorized hardware masters can access cryptographic services and secret parameters, through a communication infrastructure based on an interface protocol like AXI, and managing access rights dynamically.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a multi-master Mailbox architecture is used to enable multiple hardware masters to access the Secure Element, then communication versatility and system functionality are improved, but security is worsened because the Mailbox cannot identify or authenticate the emitters, allowing unauthorized access
Solution Approach 1:
The patent introduces a Mailbox with filtering capabilities as an intermediary between hardware masters and the Secure Element. The Mailbox receives requests from multiple masters, filters them based on authentication criteria (such as master identifiers or cryptographic keys), and only forwards authorized requests to the Secure Element. This mediator approach enables multi-master access while maintaining security by preventing unauthorized masters from directly accessing the Secure Element.
2Ease of operation
If the Mailbox accepts requests from any master without identification, then ease of operation and system simplicity are improved, but security is worsened as unauthorized masters can access sensitive data and cryptographic operations
Solution Approach 1:
The patent implements preliminary authentication and filtering actions within the Mailbox before requests reach the Secure Element. The Mailbox is pre-configured with authorization rules, master identifiers, or cryptographic keys that enable it to authenticate incoming requests in advance. This preliminary security check maintains system simplicity by keeping the authentication logic within the Mailbox rather than requiring complex changes to the Secure Element or master interfaces.
3Reliability
If a filter with authentication capabilities is added to the Mailbox to identify and authorize masters, then security is improved, but device complexity increases due to additional filtering and authentication mechanisms
Solution Approach 1:
The patent designs the Mailbox to perform multiple functions: receiving requests from multiple masters, filtering and authenticating requests, managing communication protocols, and controlling access to the Secure Element. By making the Mailbox a multi-functional component, the patent avoids the need for separate dedicated authentication hardware, thereby improving security while limiting the increase in overall device complexity. The Mailbox's universal role consolidates security functions within an existing communication infrastructure component.
Data Source
AI summary
A System on Chip includes at least two hardware masters, a security circuit, and a communication infrastructure for communication between the hardware masters and the security circuit, the communication infrastructure being based on a given interface communication protocol. Each hardware master is configured to send a request to the security circuit for execution of the request by the security circuit through the communication infrastructure, each request comprising at least one service identifier identifying a service. The security circuit may comprise a Secure Mailbox comprising a filter configured to filter the requests received from the hardware masters, the filter being configured to determine at least one indicator bit, in response to the receipt of a request from a hardware master, using at least a part of an identifier associated with the master, the indicator bit indicating whether the master is allowed access to the Security circuit, the identifier being an hardware identifier received with the request through the communication protocol, the filter filtering the requests based on the bit indicators determined for each request. The security circuit is further configured to execute the filtered requests.


