Secure SoC IP-GPIO Connections via Hardware De-multiplexing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic circuits, particularly in SoC systems, face challenges in ensuring secure data transmission between IP and GPIO entities due to vulnerabilities in data corruption and malicious software attacks, especially when multiple GPIO connections are involved, leading to inadequate security coverage and flexibility.
Innovation Solution
Implementing a hardware-based de-multiplexing feature that selectively enables or denies connections between IP and GPIO entities based on their security status, using programmable security circuits to control secure link connections in both directions, thereby enhancing security integrity and flexibility across various application scenarios.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple GPIO connections are implemented for IP entities, then flexibility and adaptability are improved, but security vulnerabilities and risk of data corruption increase
Solution Approach 1:
The patent segments the communication paths by implementing individual secure link connections for each IP-GPIO pair, with dedicated security status registers and control logic for each connection. This segmentation allows independent security management of each communication path while maintaining multiple GPIO connections for flexibility.
Solution Approach 2:
The patent introduces intermediary security circuits and control logic between IP entities and GPIO connections. These intermediaries include security status registers, comparison logic, and control circuits that mediate the communication, verifying security status before allowing data transmission and preventing direct exposure of IP entities to potential attacks.
2Reliability
If secure link connections are implemented for all IP-GPIO pairs, then security coverage is improved, but device complexity increases
Solution Approach 1:
The patent merges security management functions by implementing a unified security architecture where all secure link connections share common security status registers and control logic. The security status registers store security information for multiple IP-GPIO pairs, and the control circuits use standardized comparison and gating logic across all connections, reducing redundant complexity.
Solution Approach 2:
The patent implements universal security control circuits that can manage multiple IP-GPIO connections simultaneously. The same security status register structure, comparison logic, and gating mechanism are reused across all secure link connections, allowing a single security subsystem to provide coverage for all connections without requiring separate dedicated security circuits for each pair.
3Reliability
If hardware-based de-multiplexing is implemented for secure connections, then security control is improved, but area and timing overhead increase
Solution Approach 1:
The patent implements dynamic security control through programmable security status registers that can be configured at runtime. The de-multiplexing logic uses dynamic comparison of security statuses and configurable gating control, allowing the security behavior to adapt to different operational modes and connection requirements without hardcoding specific paths.
Solution Approach 2:
The patent changes the security status parameters stored in registers to control connection permissions. By modifying the security status values in the registers, the system dynamically enables or disables specific IP-GPIO connections based on security requirements, allowing flexible security control without changing the physical hardware structure.
Data Source
AI summary
An integrated circuit includes one or more intellectual property (IP) cores, one or more general purposes input/output (GPIO) interfaces, each GPIO interface having one or more ports, and one or more security circuits, each security circuit being coupled between an IP core and a GPIO interface. A security circuit, in operation, selectively enables communications between the IP core and the GPIO interface coupled to the security circuit based on an indication of the security status of the IP core, an indication of the security status of the GPIO interface or both the indication of the security status of the IP core and the indication of the security status of the GPIO interface.


