Security Co-Processor for Detecting Illegal Design IP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing design verification strategies for microdevices often fail to detect illegal or unintended functionality in third-party design IP, leading to potential security vulnerabilities in electronic devices.

Innovation Solution

Incorporating a security co-processor into the circuit design that monitors electronic device operations against a set of rules, initiating security actions when unauthorized or illegal activities are detected, thereby ensuring secure operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional design verification strategies are used to test third-party design IP, then functional correctness can be verified, but illegal or unintended functionality cannot be detected

Engineering Contradiction:
Improveverification capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces a security co-processor as an intermediary component that operates independently from the main processor and design IP. This co-processor specifically monitors for illegal or unintended functionality that traditional verification methods miss, while leaving the original functional verification processes intact. The security co-processor acts as a specialized mediator that fills the verification gap without disrupting existing design flows.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The verification and security monitoring functions are segmented into separate components: traditional verification tools handle functional correctness, while the security co-processor handles detection of illegal or unintended functionality. This segmentation allows each component to specialize in its specific task, improving overall detection capability without requiring complete redesign of existing verification infrastructure.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a security co-processor is added to monitor electronic device operations, then security vulnerabilities are detected, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcircuit design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security co-processor is designed with multi-functionality to justify its addition: it can monitor multiple design IP components simultaneously, detect various types of illegal or unintended functionality, and work across different design verification scenarios. This universal monitoring capability maximizes security benefits while minimizing the complexity increase per monitored function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security co-processor is configured to autonomously monitor device operations and detect security vulnerabilities without requiring constant external intervention. It independently executes monitoring tasks, generates security alerts, and can trigger security actions, reducing the operational burden on external systems and simplifying the overall security management complexity.

Inventive Principle:
Principle #25Self-service

3Productivity

If design IP from third-party vendors is utilized to accelerate development, then productivity increases, but undetected illegal operations create security risks

Engineering Contradiction:
Improvedevelopment speedVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The security co-processor is configured during the design phase to pre-establish monitoring rules and detection criteria for potential illegal or unintended functionality in third-party design IP. This preliminary configuration occurs before the design IP is fully integrated and operational, allowing security monitoring to be in place from the outset rather than requiring post-deployment patches or modifications.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9984193B1System to combat design-time vulnerability
Publication Date: 2018.05.29 SIEMENS INDUSTRY SOFTWARE INC
  • US9984193B1 patent drawing
  • US9984193B1 patent drawing
  • US9984193B1 patent drawing

AI summary

This application discloses a computing system implementing tools and mechanisms that can incorporate a security co-processor into a circuit design modeling an electronic device. The tools and mechanisms can configure the security co-processor to monitor at least a portion of the electronic device. The tools and mechanisms can generate at least one security action for the security co-processor to initiate when the security co-processor monitors the electronic device failing to conform to rules in a rules database.