Secure SoC IP-GPIO Connections via Hardware De-multiplexing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic circuits, particularly in SoC systems, face challenges in ensuring secure data transmission between IP and GPIO entities due to vulnerabilities in data corruption and malicious software attacks, especially when multiple GPIO connections are involved, leading to inadequate security coverage and flexibility.

Innovation Solution

Implementing a hardware-based de-multiplexing feature that selectively enables or denies connections between IP and GPIO entities based on their security status, using programmable security circuits to control secure link connections in both directions, thereby enhancing security integrity and flexibility across various application scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple GPIO connections are implemented for IP entities, then flexibility and adaptability are improved, but security vulnerabilities and risk of data corruption increase

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the communication paths by implementing individual secure link connections for each IP-GPIO pair, with dedicated security status registers and control logic for each connection. This segmentation allows independent security management of each communication path while maintaining multiple GPIO connections for flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary security circuits and control logic between IP entities and GPIO connections. These intermediaries include security status registers, comparison logic, and control circuits that mediate the communication, verifying security status before allowing data transmission and preventing direct exposure of IP entities to potential attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure link connections are implemented for all IP-GPIO pairs, then security coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security management functions by implementing a unified security architecture where all secure link connections share common security status registers and control logic. The security status registers store security information for multiple IP-GPIO pairs, and the control circuits use standardized comparison and gating logic across all connections, reducing redundant complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements universal security control circuits that can manage multiple IP-GPIO connections simultaneously. The same security status register structure, comparison logic, and gating mechanism are reused across all secure link connections, allowing a single security subsystem to provide coverage for all connections without requiring separate dedicated security circuits for each pair.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hardware-based de-multiplexing is implemented for secure connections, then security control is improved, but area and timing overhead increase

Engineering Contradiction:
Improvesecurity controlVSAvoidarea
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent implements dynamic security control through programmable security status registers that can be configured at runtime. The de-multiplexing logic uses dynamic comparison of security statuses and configurable gating control, allowing the security behavior to adapt to different operational modes and connection requirements without hardcoding specific paths.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the security status parameters stored in registers to control connection permissions. By modifying the security status values in the registers, the system dynamically enables or disables specific IP-GPIO connections based on security requirements, allowing flexible security control without changing the physical hardware structure.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11144678B2System with secure SoC connections among IP and multiple GPIOs, and corresponding method
Publication Date: 2021.10.12 STMICROELECTRONICS SRL
  • US11144678B2 patent drawing
  • US11144678B2 patent drawing
  • US11144678B2 patent drawing

AI summary

An integrated circuit includes one or more intellectual property (IP) cores, one or more general purposes input/output (GPIO) interfaces, each GPIO interface having one or more ports, and one or more security circuits, each security circuit being coupled between an IP core and a GPIO interface. A security circuit, in operation, selectively enables communications between the IP core and the GPIO interface coupled to the security circuit based on an indication of the security status of the IP core, an indication of the security status of the GPIO interface or both the indication of the security status of the IP core and the indication of the security status of the GPIO interface.