Semiconductor Channel Data Protection via Dedicated Encryption Modules

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Semiconductor devices face data leakage issues due to unprotected communication channels, which can be compromised through memory interfaces and hacking by other modules, leading to unauthorized data access.

Innovation Solution

Implementing a semiconductor device with multiple function modules and encryption modules that use distinct encryption keys for data encryption and decryption, ensuring each channel is protected from others, with the operating system managing key settings and storage within the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is transmitted through common bus and memory without encryption, then communication efficiency is maintained, but data security deteriorates and data leakage occurs

Engineering Contradiction:
Improvedata securityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the encryption system into separate encryption modules for different function modules. Each encryption module is associated with a specific function module and uses a dedicated encryption key, segmenting the overall encryption system to manage complexity while ensuring data security for each channel independently

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces encryption modules as intermediary components between function modules and the common bus/memory. These encryption modules act as mediators that encrypt data before transmission and decrypt received data, protecting communication channels without requiring changes to the existing bus architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption modules are added to protect each channel, then data leakage prevention is improved, but device complexity increases

Engineering Contradiction:
Improvechannel protectionVSAvoidnumber of encryption modules
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different encryption keys and encryption modules to different function modules and their respective communication channels. Each channel receives localized encryption protection tailored to its specific security requirements, rather than applying a uniform encryption approach across all channels

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The encryption modules are designed to perform multiple functions: encrypting outgoing data from their associated function module, decrypting incoming data destined for their function module, and managing their own encryption keys. This multi-functionality reduces the need for separate dedicated components for each encryption task

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10177913B2Semiconductor devices and methods of protecting data of channels in the same
Publication Date: 2019.01.08 SAMSUNG ELECTRONICS CO LTD
  • US10177913B2 patent drawing
  • US10177913B2 patent drawing
  • US10177913B2 patent drawing

AI summary

A semiconductor device may include: a bus; first and second function modules configured to communicate via the bus; a first encryption module configured to encrypt first data output from the first function module using a first encryption key to generate first encrypted data; and/or a second encryption module configured to decrypt the first encrypted data using the first encryption key, to output the decrypted first data to the second function module, and to encrypt second data output from the second function module using a second encryption key to generate second encrypted data. A semiconductor device may include: a bus; first and second modules configured to communicate via the bus; and/or an encryption module configured to use different encryption policies for first data, which is output from the first module and stored in a memory, and second data, which is output from the second module and stored in the memory.