Security Processor Fault Tolerance via Distributed Control Paths

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security systems for multimedia devices, such as set-top boxes, face challenges in providing sufficient protection against unauthorized access due to reusable passwords and complex security management, which can lead to breaches and increased hardware and software complexity.

Innovation Solution

A method and system utilizing non-volatile memory for improved fault tolerance in distributed customization controls, where an input control signal is mapped to multiple independent processing paths within a security processor, enhancing physical security by concealing the mapping function and utilizing encryption and decryption engines to manage access rights independently of the host processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passwords are used for user authentication in set-top boxes, then user identity verification is achieved, but the passwords are reusable and can be broken by attackers, leading to security breaches

Engineering Contradiction:
Improveauthentication securityVSAvoidpassword reuse and breaking vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication function from the host processor to a dedicated security processor. This separation removes the vulnerable password-based authentication mechanism from the main system and places it in an isolated security domain, preventing attackers from exploiting the host processor's authentication vulnerabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security processor acts as an intermediary between users and the host processor for all authentication operations. It mediates the authentication process by handling password verification and access control independently, preventing direct exposure of authentication credentials to the host processor and reducing the attack surface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a single security processor is used to administer security operations, then security management is centralized, but the hardware and software complexity increases significantly

Engineering Contradiction:
Improvesecurity management capabilityVSAvoidhardware and software complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security processor into distinct functional units: authentication module, authorization module, encryption module, and access control module. Each module handles specific security tasks independently, reducing overall complexity while maintaining comprehensive security management capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security processor is designed as a universal security management unit that handles multiple security functions (authentication, authorization, encryption, access control) within a single integrated architecture. This multi-functionality reduces the need for separate security components, thereby reducing hardware and software complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If access control information is stored in a single location, then security conditions are easily managed, but the system becomes vulnerable to attacks targeting that single location

Engineering Contradiction:
Improvesecurity condition managementVSAvoidsingle point of attack vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent transitions from storing access control information in a single physical location to distributing it across multiple secure locations: user credentials are stored in the security processor, while access control policies are stored in both the security processor and the host processor. This dimensional distribution creates multiple attack vectors that attackers must compromise simultaneously.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

Different types of access control information are stored in different locations with appropriate security characteristics. Sensitive user credentials are stored locally in the security processor with hardware-based protection, while access control policies are distributed to the host processor for efficient enforcement. This local quality optimization balances security and operational ease.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9497022B2Method and system for improved fault tolerance in distributed customization controls using non-volatile memory
Publication Date: 2016.11.15 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD
  • US9497022B2 patent drawing
  • US9497022B2 patent drawing
  • US9497022B2 patent drawing

AI summary

Certain aspects of a method and system for improved fault tolerance in distributed customization controls using non-volatile memory are disclosed. Aspects of one method may include mapping an input control signal to a plurality of input logic circuits within a security processor. A plurality of independent processing paths may be defined between each of the plurality of input logic circuits and an output logic circuit. Each of the plurality of independent processing paths may comprise one or more logic circuits. The input control signal may be routed via at least a portion of the plurality of independent processing paths. The portion of the plurality of independent processing paths may be combined in the output logic circuit to generate the input control signal.