On-Chip Security Controller for Off-Chip Memory Address Scrambling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional storage security protection in System on Chip (SoC) devices is inefficient and vulnerable to operating system vulnerabilities and software backdoor access, affecting CPU performance and memory access efficiency.

Innovation Solution

An off-chip memory address scrambling apparatus comprising a true random number generator, a key memory, and an on-chip security controller that performs address scrambling, ensuring secure and efficient data access by scrambling addresses in off-chip memory without impacting reading or writing efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based security protection is used, then security protection is provided, but CPU resources are occupied and system performance is lowered

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-based security mechanisms with a hardware-based security controller that performs address scrambling. This hardware implementation operates independently from the CPU, eliminating the performance overhead associated with software security while maintaining robust security protection through cryptographic address transformation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a dedicated security controller as an intermediary component between the CPU and off-chip memory. This intermediary handles all security-related address scrambling operations, allowing the CPU to focus on computation while the security controller manages protection, thus improving overall system performance without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software-based security protection is used, then security protection is provided, but memory access efficiency is lowered

Engineering Contradiction:
Improvesecurity protectionVSAvoidmemory access efficiency
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent replaces software-based security checks with hardware-based address scrambling performed by the security controller. This hardware implementation processes address transformations in parallel with memory access operations, eliminating the sequential overhead of software security checks and maintaining high memory access efficiency.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent performs address scrambling in advance by the security controller before memory access requests are processed. The scrambled addresses are pre-computed and ready when needed, allowing memory access to proceed without real-time security processing delays, thus maintaining efficient access speeds.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If conventional security mechanisms are added, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a security controller that integrates multiple security functions including address scrambling, key management, and random number generation into a single unified hardware component. This multi-functional approach provides comprehensive security protection while minimizing the increase in device complexity through functional consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The security controller is designed to operate autonomously, generating its own random numbers through an on-chip true random number generator and managing its own key storage in dedicated key memory. This self-service capability reduces the burden on other system components and minimizes overall system complexity while providing robust security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11663145B2Off-chip memory address scrambling apparatus and method for system on chip
Publication Date: 2023.05.30 C SKY MICROSYST CO LTD
  • US11663145B2 patent drawing
  • US11663145B2 patent drawing
  • US11663145B2 patent drawing

AI summary

The present disclosure provides an off-chip memory address scrambling apparatus and method for a system on chip. The apparatus includes a true random number generator, a key memory and an on-chip security controller. The on-chip security controller is connected to the true random number generator, the key memory and an off-chip memory respectively and is configured to read or write data in the off-chip memory and perform address scrambling processing on the data. The on-chip security controller includes: a memory interface module, and an address scrambling module configured to read a random key stored in the key memory, to select according to a valid/invalid state of the random key to directly invoke the read random key or read again a random key that is generated by the true random number generator and stored into the key memory, and then to perform according to the random key scrambling algorithm processing on an unscrambled address inputted by the memory interface module to form a scrambled address, and output the scrambled address to an address scrambling module of the off-chip memory. The present disclosure can improve the security while high efficiency.