Security Processor Remapping Unit for Encrypted Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure data processing systems are inflexible and require a data cache memory at the processor, limiting access and efficiency in secure data management.

Innovation Solution

A hardware security processor with a remapping unit and crossbar switch architecture allows direct access to multiple memory types, enabling secure data processing and encryption/decryption operations without the need for a dedicated data cache, using a security processor to manage encrypted data access and provide a virtual clear view of encrypted data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an access control unit is positioned between the processor and memory to provide security functions, then data security is improved, but the system becomes less flexible and requires a dedicated data cache memory at the processor

Engineering Contradiction:
Improvedata securityVSAvoidsystem flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces a security processor as an intermediary component between the processor and memory system. This security processor includes a remapping unit that intercepts and translates memory access requests, providing security functions while maintaining system flexibility. The intermediary handles encryption/decryption and address remapping without requiring the main processor to have dedicated cache memory for security operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security processor is designed to perform multiple functions: it acts as an address remapper, provides encryption/decryption services, manages security zones, and handles memory access control. This multi-functional design eliminates the need for separate dedicated cache memory at the processor while maintaining data security and system flexibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a dedicated data cache memory is required at the processor for secure data processing, then data security is improved, but memory requirements and system complexity increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security processing functions with the memory control functions in a single security processor unit. The remapping unit combines address translation, security zone management, and encryption/decryption operations into one integrated component, reducing overall system complexity while maintaining security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security processor performs self-service by autonomously handling security operations including encryption/decryption of data in transit, address remapping, and access control validation. This self-service capability eliminates the need for the main processor to manage security-specific cache memory, reducing system complexity while preserving security.

Inventive Principle:
Principle #25Self-service

3Reliability

If encrypted data must be transferred via the access control unit to cache memories, then data security is improved, but data processing efficiency decreases

Engineering Contradiction:
Improvedata securityVSAvoiddata processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security processor enables continuous data processing by performing encryption/decryption operations in parallel with memory access operations. The remapping unit continuously translates addresses and manages security zones without interrupting the main data flow, maintaining processing efficiency while ensuring security through continuous cryptographic operations.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The security processor performs preliminary encryption/decryption of data before it reaches the processor's cache memory. By pre-processing data in encrypted form and only decrypting when necessary for processor access, the system maintains security while improving efficiency by avoiding repeated encryption/decryption cycles during normal processing.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9798901B2Device having a security module
Publication Date: 2017.10.24 NXP USA INC
  • US9798901B2 patent drawing
  • US9798901B2 patent drawing
  • US9798901B2 patent drawing

AI summary

A device securely accesses data in a memory via an addressing unit which provides a memory interface for interfacing to a memory, a core interface for interfacing to a core processor and a first and second security interface. The device includes a security processor HSM for performing at least one security operation on the data and a remapping unit MMAP. The remapping unit enables the security processor to be accessed by the core processor via the first security interface and to access the memory device via the second security interface according to a remapping structure for making accessible processed data based on memory data. The device provides a clear view on encrypted memory data without requiring system memory for storing the clear data.