Secure Region Access Control Prevents Grey Manufacturing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contract manufacturers (CMs) face challenges in preventing grey manufacture, where they produce excess electronic equipment without customer support, reducing OEM profits and damaging their reputation, as existing solutions like hardware security modules (HSMs) are expensive and impractical for small production runs.

Innovation Solution

A data processing device with secure and non-secure modes, featuring a processor and memory with secure regions that can decrypt encrypted data only in secure mode, preventing unauthorized access and enabling authentication through asymmetric cryptography, allowing OEMs to securely program devices without revealing unencrypted data to CMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a hardware security module (HSM) is used to prevent grey manufacture, then security against grey manufacture is improved, but device cost and complexity increase significantly

Engineering Contradiction:
Improvesecurity against grey manufactureVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security functionality from a separate HSM device and integrates it directly into the data processing device itself. The secure region and access control mechanism are built-in components of the processor system, eliminating the need for external HSM hardware while maintaining security against grey manufacture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a simplified copy of HSM functionality within the processor. Instead of using expensive external HSM hardware, the invention implements equivalent security functions (secure key storage, encrypted data storage, access control) using software and secure memory regions within the existing processor architecture.

Inventive Principle:
Principle #26Copying

2Reliability

If a hardware security module (HSM) is used to prevent grey manufacture, then security against grey manufacture is improved, but transport and deployment become impractical for small production runs

Engineering Contradiction:
Improvesecurity against grey manufactureVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges the HSM security functions with the main processor and memory system. The secure region is integrated within the existing memory architecture, and the access control mechanism is combined with the processor's control logic, creating a unified system that is easier to manufacture and deploy than separate HSM devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent changes the implementation parameters of security functions from external hardware to internal software-based mechanisms. By implementing security in the data processing device itself rather than as external HSM hardware, the system becomes more adaptable to different production volumes and easier to manufacture.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If encrypted data is stored in non-secure memory regions, then ease of programming by CM is improved, but security of unencrypted data is compromised

Engineering Contradiction:
Improveease of programming by CMVSAvoidsecurity of cryptographic data
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the memory into secure and non-secure regions. Encrypted data can be stored in non-secure regions that are accessible during programming, while the decryption keys are stored separately in secure regions that are protected from unauthorized access. This segmentation allows CMs to program the device while maintaining security of the cryptographic data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an access control mechanism as an intermediary between the processor and memory regions. This mediator controls access based on operational mode, allowing the processor to access encrypted data in non-secure mode for programming while blocking access to decryption keys in secure regions, thus enabling both ease of programming and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If the processor can access secure memory regions in non-secure mode, then ease of data manipulation is improved, but security of cryptographic operations is compromised

Engineering Contradiction:
Improveease of data manipulationVSAvoidsecurity of cryptographic operations
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements dynamic access control based on operational mode. The access control mechanism adjusts memory accessibility dynamically: in non-secure mode, only encrypted data in non-secure regions is accessible; in secure mode, the processor can access secure regions containing decryption keys. This dynamic control enables ease of data manipulation when needed while maintaining security during cryptographic operations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10650168B2Data processing device
Publication Date: 2020.05.12 SECURE THINGZ
  • US10650168B2 patent drawing
  • US10650168B2 patent drawing
  • US10650168B2 patent drawing

AI summary

A data processing device with a processor, a memory and an access control mechanism, the device having secure and non-secure modes, the memory having secure and non-secure regions, the secure region containing cryptographic data, and the access control mechanism preventing the processor from reading the cryptographic data when the device is operating in the non-secure mode. Also, methods of manufacturing and authenticating such a device, manufacturing an item of electronic equipment that includes such a device, a computer program for storing data on such a device, secure data processing hardware including such a computer program and a method of updating data stored in an item of electronic equipment including such a data processing device.