On-Chip Security Controller for Off-Chip Memory Address Scrambling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional storage security protection in System on Chip (SoC) devices is inefficient and vulnerable to operating system vulnerabilities and software backdoor access, affecting CPU performance and memory access efficiency.
Innovation Solution
An off-chip memory address scrambling apparatus comprising a true random number generator, a key memory, and an on-chip security controller that performs address scrambling, ensuring secure and efficient data access by scrambling addresses in off-chip memory without impacting reading or writing efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software-based security protection is used, then security protection is provided, but CPU resources are occupied and system performance is lowered
Solution Approach 1:
The patent replaces software-based security mechanisms with a hardware-based security controller that performs address scrambling. This hardware implementation operates independently from the CPU, eliminating the performance overhead associated with software security while maintaining robust security protection through cryptographic address transformation.
Solution Approach 2:
The patent introduces a dedicated security controller as an intermediary component between the CPU and off-chip memory. This intermediary handles all security-related address scrambling operations, allowing the CPU to focus on computation while the security controller manages protection, thus improving overall system performance without compromising security.
2Reliability
If software-based security protection is used, then security protection is provided, but memory access efficiency is lowered
Solution Approach 1:
The patent replaces software-based security checks with hardware-based address scrambling performed by the security controller. This hardware implementation processes address transformations in parallel with memory access operations, eliminating the sequential overhead of software security checks and maintaining high memory access efficiency.
Solution Approach 2:
The patent performs address scrambling in advance by the security controller before memory access requests are processed. The scrambled addresses are pre-computed and ready when needed, allowing memory access to proceed without real-time security processing delays, thus maintaining efficient access speeds.
3Reliability
If conventional security mechanisms are added, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements a security controller that integrates multiple security functions including address scrambling, key management, and random number generation into a single unified hardware component. This multi-functional approach provides comprehensive security protection while minimizing the increase in device complexity through functional consolidation.
Solution Approach 2:
The security controller is designed to operate autonomously, generating its own random numbers through an on-chip true random number generator and managing its own key storage in dedicated key memory. This self-service capability reduces the burden on other system components and minimizes overall system complexity while providing robust security.
Data Source
AI summary
The present disclosure provides an off-chip memory address scrambling apparatus and method for a system on chip. The apparatus includes a true random number generator, a key memory and an on-chip security controller. The on-chip security controller is connected to the true random number generator, the key memory and an off-chip memory respectively and is configured to read or write data in the off-chip memory and perform address scrambling processing on the data. The on-chip security controller includes: a memory interface module, and an address scrambling module configured to read a random key stored in the key memory, to select according to a valid/invalid state of the random key to directly invoke the read random key or read again a random key that is generated by the true random number generator and stored into the key memory, and then to perform according to the random key scrambling algorithm processing on an unscrambled address inputted by the memory interface module to form a scrambled address, and output the scrambled address to an address scrambling module of the off-chip memory. The present disclosure can improve the security while high efficiency.


