Secure SoC Memory Isolation for Replay-Resistant Data Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure processors face challenges in providing a completely independent security environment due to differences in manufacturing processes between processors and memories, leading to vulnerabilities such as data deletion and replay attacks when secure data is stored in general memory.

Innovation Solution

Integration of a secure processor and memory into a single System-on-Chip (SoC) to create a secure execution environment, where a secure processor operates in a security environment and controls data security using a first security key, while a secure memory stores a corresponding second security key, ensuring independent and safe storage of secure data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If secure data is stored in general memory to enable data storage functionality, then storage capacity is improved, but security reliability deteriorates due to unauthorized access and deletion risks

Engineering Contradiction:
Improvestorage capacityVSAvoidsecurity reliability
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent segments the memory into distinct secure and non-secure regions. The secure memory region is physically separated and controlled by the secure processor, while the non-secure region is accessible by the general processor. This segmentation allows the system to maintain both storage capacity and security reliability by storing sensitive data in the isolated secure region.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure processor as an intermediary between the general processor and the secure memory region. This intermediary controls all access to secure data, encrypting data before it can be stored in the secure region and decrypting it for authorized access. This mediator prevents unauthorized access while maintaining storage functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If secure processor and memory are integrated into one chip to improve manufacturing efficiency, then device complexity is reduced, but manufacturing precision becomes more difficult due to different manufacturing processes

Engineering Contradiction:
Improvedevice complexityVSAvoidmanufacturing precision
Core Design Contradiction:
Device complexityVSManufacturing precision

Solution Approach 1:

The patent merges the secure processor and secure memory onto a single system chip, integrating previously separate components. This consolidation reduces device complexity by eliminating the need for external secure memory chips and their associated interfaces, while the different manufacturing processes are coordinated through shared manufacturing infrastructure and timing synchronization.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3709205B1Electronic device including secure integrated circuit
Publication Date: 2024.02.28 SAMSUNG ELECTRONICS CO LTD
  • EP3709205B1 patent drawingFigure 1
  • EP3709205B1 patent drawingFigure 2
  • EP3709205B1 patent drawingFigure 3

AI summary

An electronic device including a secure Integrated Circuit (IC) is provided. The electronic device includes a secure IC configured as a System-on-Chip (SoC) and configured to provide a general environment and a security environment, wherein the secure IC includes a main processor configured to operate in the general environment, a secure processor configured to operate in the security environment and control security of data using a first security key, and a secure memory configured to be operatively connected to the secure processor and store a second security key corresponding to the first security key. Various other embodiments are possible.