Semiconductor Device Security via Dual-Control Program Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Semiconductor devices with communication functions face reliability issues due to unauthorized access, as existing solutions either fail to secure the system or disrupt its operation upon detecting unauthorized access, leading to potential software tampering and loss of functionality.
Innovation Solution
A semiconductor device comprising a main control device and a sub-control device, where the main control device outputs a trigger signal upon detecting abnormal processing, triggering the sub-control device to supply a sub-program that replaces the main program, thereby securing the system without external communication functionality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If memory protection function is implemented to detect unauthorized access, then system security is improved, but system operation is disrupted when unauthorized access is detected
Solution Approach 1:
A sub-program is prepared in advance in the sub-control device as a backup security measure. When unauthorized access is detected by the main control device, the system can immediately switch to the pre-prepared sub-program without interruption, maintaining both security and operational continuity.
Solution Approach 2:
The sub-control device acts as an intermediary between the main control device and the external environment. When unauthorized access is detected, the sub-control device receives the trigger signal and supplies the sub-program, serving as a mediator that enables secure program switching without disrupting system operation.
2Reliability
If main microcomputer operation is prohibited after unauthorized access detection, then system security is improved, but device functionality is lost
Solution Approach 1:
The system dynamically switches between the main program and sub-program based on security conditions. Instead of permanently prohibiting operation, the main control device can restore normal functionality by loading a new main program after security threats are addressed, maintaining both security and adaptability.
Solution Approach 2:
When unauthorized access is detected, the compromised main program is discarded and replaced with the secure sub-program. After the security issue is resolved, a new main program can be recovered and loaded, allowing the system to regain full functionality while maintaining security protections.
3Reliability
If program switching is implemented to respond to unauthorized access, then system security is improved, but system complexity increases
Solution Approach 1:
The control system is segmented into two independent parts: the main control device handling normal operations and the sub-control device handling security responses. This segmentation allows complex security functions to be isolated in the sub-control device without complicating the main control logic.
Solution Approach 2:
The sub-control device is self-contained with its own program memory and execution capabilities. It autonomously receives trigger signals from the main control device and supplies the appropriate sub-program without requiring external intervention, simplifying the overall system architecture.
Data Source
AI summary
A semiconductor device and the like for maintaining a required function while suppressing unauthorized accesses are provided. The semiconductor device 100 includes a main control device 110 and a sub-control device 120. The main control device 110 includes a main memory 112 for storing main programs for receiving external signals, and a trigger signal output circuit 115 for outputting a trigger signal when an abnormal signal process differs from preset signal processing is performed. The sub-control device 120 is coupled to the main control device 110, and includes a trigger signal obtaining circuit 121 for obtaining a trigger signal, and a sub-program outputting circuit 123 for outputting a sub-program to the main control device 110 based on the obtained trigger signal.


