Semiconductor Device Security via Dual-Control Program Switching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Semiconductor devices with communication functions face reliability issues due to unauthorized access, as existing solutions either fail to secure the system or disrupt its operation upon detecting unauthorized access, leading to potential software tampering and loss of functionality.

Innovation Solution

A semiconductor device comprising a main control device and a sub-control device, where the main control device outputs a trigger signal upon detecting abnormal processing, triggering the sub-control device to supply a sub-program that replaces the main program, thereby securing the system without external communication functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If memory protection function is implemented to detect unauthorized access, then system security is improved, but system operation is disrupted when unauthorized access is detected

Engineering Contradiction:
Improvesystem securityVSAvoidsystem operation continuity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

A sub-program is prepared in advance in the sub-control device as a backup security measure. When unauthorized access is detected by the main control device, the system can immediately switch to the pre-prepared sub-program without interruption, maintaining both security and operational continuity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The sub-control device acts as an intermediary between the main control device and the external environment. When unauthorized access is detected, the sub-control device receives the trigger signal and supplies the sub-program, serving as a mediator that enables secure program switching without disrupting system operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If main microcomputer operation is prohibited after unauthorized access detection, then system security is improved, but device functionality is lost

Engineering Contradiction:
Improvesystem securityVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically switches between the main program and sub-program based on security conditions. Instead of permanently prohibiting operation, the main control device can restore normal functionality by loading a new main program after security threats are addressed, maintaining both security and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

When unauthorized access is detected, the compromised main program is discarded and replaced with the secure sub-program. After the security issue is resolved, a new main program can be recovered and loaded, allowing the system to regain full functionality while maintaining security protections.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If program switching is implemented to respond to unauthorized access, then system security is improved, but system complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidcontrol structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The control system is segmented into two independent parts: the main control device handling normal operations and the sub-control device handling security responses. This segmentation allows complex security functions to be isolated in the sub-control device without complicating the main control logic.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The sub-control device is self-contained with its own program memory and execution capabilities. It autonomously receives trigger signals from the main control device and supplies the appropriate sub-program without requiring external intervention, simplifying the overall system architecture.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11599631B2Semiconductor device, semiconductor system and program
Publication Date: 2023.03.07 RENESAS ELECTRONICS CORP
  • US11599631B2 patent drawing
  • US11599631B2 patent drawing
  • US11599631B2 patent drawing

AI summary

A semiconductor device and the like for maintaining a required function while suppressing unauthorized accesses are provided. The semiconductor device 100 includes a main control device 110 and a sub-control device 120. The main control device 110 includes a main memory 112 for storing main programs for receiving external signals, and a trigger signal output circuit 115 for outputting a trigger signal when an abnormal signal process differs from preset signal processing is performed. The sub-control device 120 is coupled to the main control device 110, and includes a trigger signal obtaining circuit 121 for obtaining a trigger signal, and a sub-program outputting circuit 123 for outputting a sub-program to the main control device 110 based on the obtained trigger signal.