Security Processor NVM Architecture for Low-Power Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data security systems face challenges in securely managing keys to protect data from advanced attacks, particularly in scenarios where power consumption and operational modes need to be balanced.
Innovation Solution
An electronic device is designed with a system on chip (SOC) that includes a security processor and non-volatile memory (NVM) to store security data, allowing secure data processing and management across normal and low power modes, with separate power supply to the security processor ensuring independent operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security processor is always powered on to ensure secure key management, then data security is improved, but power consumption increases
Solution Approach 1:
The power supply to the security processor is made dynamic rather than static. The controller selectively powers on the security processor only when security operations are required, and powers it down during normal operations. This dynamic power management maintains data security when needed while reducing overall power consumption.
Solution Approach 2:
The operational state of the security processor is changed between different power modes. The controller adjusts the power supply parameter of the security processor based on operational requirements, switching between powered-on and powered-off states to balance security needs with power consumption constraints.
2Use of energy by moving object
If the security processor is powered down to reduce power consumption, then power efficiency is improved, but data security management capability deteriorates
Solution Approach 1:
The controller prepares and manages security operations in advance by selectively activating the security processor before security-critical tasks are needed. This preliminary action ensures that the security processor is ready when required, maintaining security management capability while allowing it to remain powered down during non-security periods.
Solution Approach 2:
The system implements self-service security management where the controller autonomously determines when to power on/off the security processor based on operational context. This self-service mechanism ensures security capabilities are available when needed without requiring continuous power supply.
3Extent of automation
If security data is stored in the first NVM requiring SOC access, then centralized security management is achieved, but access complexity and potential attack surfaces increase
Solution Approach 1:
The controller acts as an intermediary between the SOC and the first NVM for security data access. It selectively provides access to the security processor when needed, mediating the interaction between the centralized storage system and the security operations. This reduces direct access complexity while maintaining centralized management benefits.
Data Source
AI summary
An electronic device which operates in a normal mode or a low power mode includes a system on chip (SOC), a first non-volatile memory (NVM), and a security device including a second NVM and a memory processor. The first NVM includes a security region and a non-security region. The SOC includes a main processor a memory controller and a security processor connected to the main processor and the memory controller. The security processor generates a write request signal and first security data. In the normal mode, the security processor stores the first security data in the security region of the first NVM in response to the main processor of the SOC being activated and stores the first security data in the second NVM in response to the memory processor of the security device being activated.


