Secure Region Access Control Prevents Grey Manufacturing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contract manufacturers (CMs) face challenges in preventing grey manufacture, where they produce excess electronic equipment without customer support, reducing OEM profits and damaging their reputation, as existing solutions like hardware security modules (HSMs) are expensive and impractical for small production runs.
Innovation Solution
A data processing device with secure and non-secure modes, featuring a processor and memory with secure regions that can decrypt encrypted data only in secure mode, preventing unauthorized access and enabling authentication through asymmetric cryptography, allowing OEMs to securely program devices without revealing unencrypted data to CMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hardware security module (HSM) is used to prevent grey manufacture, then security against grey manufacture is improved, but device cost and complexity increase significantly
Solution Approach 1:
The patent extracts the security functionality from a separate HSM device and integrates it directly into the data processing device itself. The secure region and access control mechanism are built-in components of the processor system, eliminating the need for external HSM hardware while maintaining security against grey manufacture.
Solution Approach 2:
The patent creates a simplified copy of HSM functionality within the processor. Instead of using expensive external HSM hardware, the invention implements equivalent security functions (secure key storage, encrypted data storage, access control) using software and secure memory regions within the existing processor architecture.
2Reliability
If a hardware security module (HSM) is used to prevent grey manufacture, then security against grey manufacture is improved, but transport and deployment become impractical for small production runs
Solution Approach 1:
The patent merges the HSM security functions with the main processor and memory system. The secure region is integrated within the existing memory architecture, and the access control mechanism is combined with the processor's control logic, creating a unified system that is easier to manufacture and deploy than separate HSM devices.
Solution Approach 2:
The patent changes the implementation parameters of security functions from external hardware to internal software-based mechanisms. By implementing security in the data processing device itself rather than as external HSM hardware, the system becomes more adaptable to different production volumes and easier to manufacture.
3Ease of operation
If encrypted data is stored in non-secure memory regions, then ease of programming by CM is improved, but security of unencrypted data is compromised
Solution Approach 1:
The patent segments the memory into secure and non-secure regions. Encrypted data can be stored in non-secure regions that are accessible during programming, while the decryption keys are stored separately in secure regions that are protected from unauthorized access. This segmentation allows CMs to program the device while maintaining security of the cryptographic data.
Solution Approach 2:
The patent introduces an access control mechanism as an intermediary between the processor and memory regions. This mediator controls access based on operational mode, allowing the processor to access encrypted data in non-secure mode for programming while blocking access to decryption keys in secure regions, thus enabling both ease of programming and security.
4Ease of operation
If the processor can access secure memory regions in non-secure mode, then ease of data manipulation is improved, but security of cryptographic operations is compromised
Solution Approach 1:
The patent implements dynamic access control based on operational mode. The access control mechanism adjusts memory accessibility dynamically: in non-secure mode, only encrypted data in non-secure regions is accessible; in secure mode, the processor can access secure regions containing decryption keys. This dynamic control enables ease of data manipulation when needed while maintaining security during cryptographic operations.
Data Source
AI summary
A data processing device with a processor, a memory and an access control mechanism, the device having secure and non-secure modes, the memory having secure and non-secure regions, the secure region containing cryptographic data, and the access control mechanism preventing the processor from reading the cryptographic data when the device is operating in the non-secure mode. Also, methods of manufacturing and authenticating such a device, manufacturing an item of electronic equipment that includes such a device, a computer program for storing data on such a device, secure data processing hardware including such a computer program and a method of updating data stored in an item of electronic equipment including such a data processing device.


