Secure Processing Module with Remote Fabrication Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure processor designs require protected fabrication facilities to prevent unauthorized access and tampering, limiting fabrication options and increasing costs, as well as being vulnerable to malware introduction during manufacturing.

Innovation Solution

The development of a trustworthy electronic processing module with a Secure Processor ANGEL Network (SPAN) feature that allows remote monitoring and verification of manufacturing processes, using DASH technology to ensure the chip does not contain hidden malware, enabling secure manufacturing in untrusted facilities and trusted networking with other devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protected information is installed prior to application of anti-tamper mesh during fabrication, then secure processor design is achieved, but fabrication facility must be protected from unauthorized access and modification is limited

Engineering Contradiction:
ImprovesecurityVSAvoidfabrication flexibility
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The processor design is divided into two segments: a public portion that can be manufactured in untrusted facilities, and a protected portion (security envelope) that is applied separately. This segmentation allows the bulk of manufacturing to occur without special security measures while maintaining security through the separate application of the security envelope containing the protected information.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security envelope is prepared in advance with the protected information embedded, then applied to the processor after fabrication. This preliminary preparation of the security component allows the main fabrication process to proceed without requiring protected facilities, while still ensuring security through the pre-prepared protective layer.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If anti-tamper mesh is applied to protect processor, then secrets are protected from tampering, but modification of protected information is limited and fabrication options are reduced

Engineering Contradiction:
Improvetamper protectionVSAvoidfabrication options
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security envelope acts as an intermediary layer between the processor core and the external environment. It mediates the conflict between protection and flexibility by providing tamper protection while allowing the processor to be manufactured using standard, untrusted fabrication processes. The envelope is applied after fabrication, serving as a protective mediator that doesn't constrain manufacturing options.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If fabrication facility is protected from unauthorized access, then secrets are not discovered, but costs increase and fabrication options are limited

Engineering Contradiction:
Improvesecret protectionVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The manufacturing process is segmented into two parts: fabrication of the processor body in untrusted, cost-effective facilities, and separate application of the security envelope containing protected information. This segmentation eliminates the need for expensive protected fabrication facilities while maintaining secret protection through the separate security component.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protected information is copied into the security envelope during a controlled process, then the envelope is applied to the processor. This copying approach allows the protected information to be securely embedded without requiring the entire fabrication facility to be protected, reducing costs while maintaining security.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8930717B2Secure processing module and method for making the same
Publication Date: 2015.01.06 ANGEL SECURE NETWORKS INC
  • US8930717B2 patent drawing
  • US8930717B2 patent drawing
  • US8930717B2 patent drawing

AI summary

Described herein are devices and techniques related to implementation of a trustworthy electronic processing module. During fabrication, a manufacturer is provided with partial technical specifications that intentionally exclude at least one critical design feature. Fabrication of the electronic processing module is monitored from a trusted remote location; wherefrom, the intentionally excluded at least one critical design feature is implemented, thereby completing manufacture of the trustworthy electronic processing module. At least one of the acts of monitoring and implementing can be accomplished by instantiating executable software remotely from a trusted remote location and immediately prior to execution. It is the executable software that enables at least one of the acts of monitoring and implementing. Further, the instantiated executable software is removed or otherwise rendered inoperable immediately subsequent to execution. In some embodiments the critical design feature can be implemented within a configurable element, such as a field programmable gate array (FPGA).