Security Processor NVM Architecture for Low-Power Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems face challenges in securely managing keys to protect data from advanced attacks, particularly in scenarios where power consumption and operational modes need to be balanced.

Innovation Solution

An electronic device is designed with a system on chip (SOC) that includes a security processor and non-volatile memory (NVM) to store security data, allowing secure data processing and management across normal and low power modes, with separate power supply to the security processor ensuring independent operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security processor is always powered on to ensure secure key management, then data security is improved, but power consumption increases

Engineering Contradiction:
Improvedata securityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The power supply to the security processor is made dynamic rather than static. The controller selectively powers on the security processor only when security operations are required, and powers it down during normal operations. This dynamic power management maintains data security when needed while reducing overall power consumption.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The operational state of the security processor is changed between different power modes. The controller adjusts the power supply parameter of the security processor based on operational requirements, switching between powered-on and powered-off states to balance security needs with power consumption constraints.

Inventive Principle:
Principle #35Parameter changes

2Use of energy by moving object

If the security processor is powered down to reduce power consumption, then power efficiency is improved, but data security management capability deteriorates

Engineering Contradiction:
Improvepower consumptionVSAvoidsecurity management capability
Core Design Contradiction:
Use of energy by moving objectVSReliability

Solution Approach 1:

The controller prepares and manages security operations in advance by selectively activating the security processor before security-critical tasks are needed. This preliminary action ensures that the security processor is ready when required, maintaining security management capability while allowing it to remain powered down during non-security periods.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service security management where the controller autonomously determines when to power on/off the security processor based on operational context. This self-service mechanism ensures security capabilities are available when needed without requiring continuous power supply.

Inventive Principle:
Principle #25Self-service

3Extent of automation

If security data is stored in the first NVM requiring SOC access, then centralized security management is achieved, but access complexity and potential attack surfaces increase

Engineering Contradiction:
Improvecentralized security managementVSAvoidaccess complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The controller acts as an intermediary between the SOC and the first NVM for security data access. It selectively provides access to the security processor when needed, mediating the interaction between the centralized storage system and the security operations. This reduces direct access complexity while maintaining centralized management benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12554897B2Electronic device
Publication Date: 2026.02.17 SAMSUNG ELECTRONICS CO LTD
  • US12554897B2 patent drawing
  • US12554897B2 patent drawing
  • US12554897B2 patent drawing

AI summary

An electronic device which operates in a normal mode or a low power mode includes a system on chip (SOC), a first non-volatile memory (NVM), and a security device including a second NVM and a memory processor. The first NVM includes a security region and a non-security region. The SOC includes a main processor a memory controller and a security processor connected to the main processor and the memory controller. The security processor generates a write request signal and first security data. In the normal mode, the security processor stores the first security data in the security region of the first NVM in response to the main processor of the SOC being activated and stores the first security data in the second NVM in response to the memory processor of the security device being activated.