Secure SoC Configuration via Cryptographic Manager
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current system-on-a-chip (SoC) configuration methods are inflexible and costly, requiring multiple fuses for redundancy and limiting the ability to reconfigure ICs after initial sale, which restricts revenue streams and inventory efficiency due to inefficient stockpiling and delayed order fulfillment.
Innovation Solution
A secure asset management infrastructure, including a multi-device cryptographic manager system, allows for secure configuration, customization, and testing of SoCs through a network of devices, enabling secure key management and feature activation, reducing the need for physical inventory and enabling remote manufacturing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple fuses are added to IC for configuration redundancy, then configuration flexibility is improved, but device complexity and manufacturing cost increase
Solution Approach 1:
The patent uses a master copy of configuration data stored in secure memory that can be replicated and programmed into the IC multiple times. This allows flexible reconfiguration without adding physical redundancy elements like multiple fuses, as the same master configuration can be copied as needed.
Solution Approach 2:
The patent extracts the configuration data from physical fuse elements and stores it in a separate secure memory location (master copy). This separation allows the configuration to be modified and reprogrammed without affecting the physical IC structure, eliminating the need for multiple fuses while maintaining flexibility.
2Adaptability or versatility
If IC configuration is performed by vendors with multiple fuse settings, then configuration capability is improved, but inventory efficiency deteriorates
Solution Approach 1:
The patent implements dynamic reconfiguration capability where the IC can change its configuration after manufacturing. The master copy in secure memory can be updated and the changes applied to the operational IC, allowing the same physical IC to adapt to different applications without requiring multiple pre-configured inventory variants.
Solution Approach 2:
The patent makes a single IC design universal by enabling it to perform multiple configurations through software-based reprogramming. The same hardware platform can be configured for different applications by updating the master copy in secure memory, eliminating the need to maintain separate inventory stocks for different configurations.
3Reliability
If secure keys are stored in one-time programmable memory, then security is improved, but reconfiguration capability deteriorates
Solution Approach 1:
The patent segments the security architecture into two parts: a secure immutable master copy stored in one-time programmable memory for security, and a configurable working copy that can be modified. This segmentation maintains security through the OTP-protected master while enabling reconfiguration through the modifiable working copy.
Solution Approach 2:
The patent introduces an intermediary secure memory system that acts as a master copy holding the authoritative configuration. This intermediary layer allows secure verification against the OTP-stored master while permitting controlled modifications to the operational configuration, bridging security and flexibility requirements.
Data Source
AI summary
The embodiments described herein describe technologies for Module management, including Module creation and Module deployment to a target device in an operation phase of a manufacturing lifecycle of the target device in a cryptographic manager (CM) environment. One implementation includes a Root Authority (RA) device that receives a first command to create a Module and executes a Module Template to generate the Module in response to the first command. The RA device receives a second command to create a deployment authorization message. The Module and the deployment authorization message are deployed to an Appliance device. A set of instructions of the Module, when permitted by the deployment authorization message and executed by the Appliance device, results in a secure construction of a sequence of operations to securely provision a data asset to the target device.


