Secure Router IC for Cyber Security Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Devices connected over IP, such as smartphones and medical monitoring equipment, are vulnerable to hostile attacks due to lack of security, posing risks to data integrity and human safety.
Innovation Solution
An integrated circuit (IC) with a secure router, non-volatile RAM DMA channels, a secure boot/key controller, and a processor that implements Suite B algorithms for encryption, intrusion detection, and key management, enabling secure boot processes and data validation across different security classifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security features are added to protect against cyber attacks, then security reliability is improved, but device complexity increases
Solution Approach 1:
The integrated circuit is divided into multiple security domains including a secure boot domain with trust anchor, a secure router domain with security policy enforcement, and application domains. Each domain has dedicated hardware components (secure boot/key controller, secure router with DMA channels) that operate independently but coordinate through defined interfaces, distributing security functions across segmented modules rather than concentrating all security logic in a single complex unit.
Solution Approach 2:
The patent introduces a vertical hierarchy of security domains layered above the base processor architecture. The trust anchor and secure router operate as separate security layers that intercept and validate operations before they reach the application layer, adding a dimensional layer of security validation without fundamentally redesigning the entire processor architecture.
2Reliability
If multiple security domains and validation processes are implemented, then security reliability is improved, but processing time increases
Solution Approach 1:
Security validation is performed in advance through a secure boot process that validates the security policy and establishes trust anchors before the system begins normal operation. The trust anchor pre-loads security credentials and the secure router pre-configures security rules, so that during runtime, data validation can proceed efficiently with pre-established security parameters rather than performing full validation on every operation.
Solution Approach 2:
The secure router acts as an intermediary component between the secure boot domain and the application domain. It receives validated security parameters from the trust anchor and enforces security policies on data flows between domains, mediating security validation in a dedicated hardware component rather than burdening the main processor with time-consuming validation operations.
3Reliability
If encryption and key management functions are integrated into the processor, then security reliability is improved, but power consumption increases
Solution Approach 1:
Encryption and key management functions are extracted from the general-purpose processor and implemented as dedicated hardware modules within the secure boot domain. The trust anchor contains specialized key management logic and the secure router includes encryption/decryption capabilities, separating security-critical cryptographic operations from the main processor to enable efficient, low-power cryptographic processing.
4Reliability
If data validation against security policy is performed at multiple stages, then security reliability is improved, but device complexity increases
Solution Approach 1:
The secure router is designed as a universal security enforcement point that handles multiple security validation functions through a single integrated component. It performs data classification, security policy validation, encryption/decryption, and domain routing all through one hardware module, reducing the need for separate validation components for each function while maintaining multi-stage security checks.
Data Source
AI summary
In one aspect, an integrated circuit (IC) includes a secure router configured as a trust anchor, a non-volatile random access memory (RAM) direct memory access (DMA) channel coupled to the secure router, a first DMA coupled to the secure router and configured to receive data with a first classification and a second DMA coupled to the secure router and configured to receive data with a second classification. The IC also includes a secure boot/key controller coupled to the secure router and configured as a trust anchor to boot the IC securely and a processor coupled to the secure router and configured to encrypt data, to store protocols, to store instructions to detect malicious intrusions on the IC and to provide key management.


