Secure SOC Architecture for Multimedia Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multimedia systems face challenges in managing security operations due to increased complexity and the need for large amounts of memory to handle multiple user modes and security components, which can lead to security breaches and implementation difficulties.

Innovation Solution

A secure system-on-a-chip (SOC) architecture that configures subsystems via unsecured buses and enables secure functionalities through a security processor using secure buses, allowing for programming of security registers, data routing, and key loading, while validating code execution to manage security operations efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single security processor is used to administer security operations in a multimedia system, then security management is centralized and control is simplified, but the system becomes vulnerable to security breaches and cannot adequately handle multiple user modes and security components

Engineering Contradiction:
Improvesecurity management complexityVSAvoidsecurity protection level
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the security management function into two separate processors: a host processor that configures subsystems and a security processor that enables secure functionalities. This segmentation allows each processor to specialize in its respective function, improving both the complexity management and security reliability simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces secure buses as an intermediary communication channel between the host processor and security processor. This intermediary mechanism ensures that security-critical communications are isolated from unsecured channels, maintaining security protection while enabling coordinated operation between processors.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If large amounts of memory are allocated to handle multiple user modes and security components, then comprehensive security coverage is achieved, but hardware complexity and implementation difficulty increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments security configuration into two phases: initial configuration of subsystems via unsecured buses, and subsequent enabling of secure functionalities via secure buses. This segmentation allows memory to be used efficiently for security purposes only when needed, rather than allocating large amounts of memory for all possible security scenarios simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The host processor performs preliminary configuration of subsystems before the security processor enables secure functionalities. This preliminary action allows the system to establish basic operational parameters using simpler unsecured communication, then layer security on top without requiring all security infrastructure to be in place from the start.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If unsecured buses are used for configuring subsystems, then configuration flexibility and ease of setup are improved, but security vulnerabilities are introduced

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsecurity security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the communication infrastructure into unsecured buses for configuration purposes and secure buses for security-critical operations. This segmentation allows each communication channel to be optimized for its specific purpose: flexibility for configuration, security for protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs subsystem configuration via unsecured buses as a preliminary step before activating secure functionalities. This preliminary configuration phase establishes the operational framework, after which the security processor takes control through secure buses to enable protected operations.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If secure buses are used for enabling secure functionalities, then security protection is enhanced, but system complexity and implementation difficulty increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the bus system into unsecured and secure channels, each serving distinct purposes. The secure buses are exclusively used for security-critical communications between the host processor and security processor, providing enhanced protection without requiring all system communications to use complex secure protocols.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure buses act as an intermediary communication channel that mediates all security-critical interactions. This intermediary layer provides standardized security handling, reducing the complexity that would otherwise be distributed across multiple custom security implementations throughout the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP1826694B1Method and system for secure system-on-a-chip architecture for multimedia data processing
Publication Date: 2014.08.06 BROADCOM INC
  • EP1826694B1 patent drawingFigure 1
  • EP1826694B1 patent drawingFigure 2A
  • EP1826694B1 patent drawingFigure 2B

AI summary

Aspects of a method and apparatus for a secure system-on-a-chip (SOC) architecture for multimedia data processing are provided. A processor may configure at least one subsytem within the SOC via at least one unsecured bus while a security processor enables secure functionalities in configured subsytems via at least one secure bus. The unsecure buses may comprise a data bus and/or a control bus, for example. The secure buses may comprise a secure control bus and/or a secure key bus, for example. The configurable subsystems may be multimedia processing units, input and output modules, and/or memory controllers. The security processor may program bits in security registers within the subsystems to enable secure functionalities, such as data routing paths and/or key loading paths, for example. Moreover, the security processor may validate code to be executed by a processor for configuring the SOC subsystems.