Security Processor Key Distribution for System-on-Chip Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory management systems in computing systems face challenges in efficiently distributing and managing keys for secure communication and operations, particularly in system on chip environments, where secure communication protocols are not adequately addressed.

Innovation Solution

A key distribution system utilizing a security processor to manage and distribute keys through a private key distribution bus, ensuring secure communication by generating and allocating keys based on the security mode, and centrally controlling key distribution and destruction based on component connections and mode changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a key distribution system is implemented in a system on chip environment, then secure communication is enabled, but hardware resource usage increases

Engineering Contradiction:
Improvesecure communicationVSAvoidhardware resource usage
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the key distribution functionality with the existing memory management module, integrating the security processor and key distribution bus into the existing system architecture. This merging approach enables secure communication while minimizing additional hardware overhead by reusing existing structural components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The memory management module is designed to perform both traditional memory management functions and key distribution functions. The security processor can operate in different modes (secure mode and non-secure mode) to serve multiple purposes, reducing the need for dedicated hardware components solely for key distribution.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If keys are distributed to multiple submodules, then secure operations are enabled, but key management complexity increases

Engineering Contradiction:
Improvesecure operationsVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements a feedback mechanism where the security processor monitors submodule connections and security mode changes. When a submodule connects or the security mode changes, the system automatically responds by distributing or destroying keys accordingly, reducing manual key management complexity while maintaining security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The key distribution system operates autonomously based on connection events and security mode changes. The security processor automatically determines when keys need to be distributed or destroyed without external intervention, enabling secure operations while simplifying key management through self-service automation.

Inventive Principle:
Principle #25Self-service

3Reliability

If secure mode is enforced for all communications, then security is improved, but system performance decreases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts the security mode based on the specific communication requirements. The security processor can switch between secure mode and non-secure mode depending on whether the communicating submodules require encryption, allowing the system to optimize performance by applying security only when necessary rather than enforcing it universally.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12413568B2Method and system for distributing keys
Publication Date: 2025.09.09 ADVANCED MICRO DEVICES INC
  • US12413568B2 patent drawing
  • US12413568B2 patent drawing
  • US12413568B2 patent drawing

AI summary

A method and system for distributing keys in a key distribution system includes receiving a connection for communication from a first component. A determination is made whether the first component requires a key be generated and distributed. Based upon a security mode for the communication, the key generated and distributed to the first component.