Shielded Hard Macro Bus Authentication for Secure SoC Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The integration of hard macros in System-on-Chip (SOC) circuits is complex and time-consuming, leading to prolonged design-to-production cycles due to the need for customizing microcontrollers to host these macros, and existing security measures are vulnerable to malicious attacks.
Innovation Solution
Implementing a secure and independent bus system using standard interfaces to manage hard macros as external peripherals, coupled with a shielded bus and detection mechanisms to prevent unauthorized access and malicious activities, ensuring secure communication and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hard macros are integrated into the same die as the microcontroller using existing security measures (Trust Zone, Resource Isolation Framework), then communication security is granted, but the design complexity and production time are significantly increased
Solution Approach 1:
The patent segments the communication interface into two distinct parts: a public interface for general communication and a secure interface for authenticated communication. This segmentation allows standard hard macros to be used without complex customization while maintaining security through the separate secure interface that requires authentication tokens.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism using tokens that mediate between the microcontroller and hard macros. This token-based authentication system acts as a mediator that grants or denies access to the secure interface, eliminating the need for complex Trust Zone or Resource Isolation Framework implementations.
2Reliability
If hard macros are customized to host secure communication with the microcontroller, then security is improved, but the production time and design cycle are prolonged
Solution Approach 1:
The patent creates a universal secure communication interface that can be used with any standard hard macro without customization. The secure interface with token-based authentication is designed to be compatible with existing hard macro architectures, allowing the same security mechanism to be applied across different hard macros (UWB, BLE, Wi-Fi, etc.) without requiring separate customization for each.
Solution Approach 2:
The authentication tokens are pre-configured and stored in the hard macros during manufacturing. This preliminary action of pre-loading authentication credentials eliminates the need for complex runtime security configurations and customization during the design phase, thereby reducing production time while maintaining security.
3Device complexity
If standard interfaces are used to manage hard macros as external peripherals, then design simplicity is improved, but security against malicious attacks is weakened
Solution Approach 1:
The patent segments the interface into public and secure components. The public interface uses standard protocols for simplicity, while the secure interface requires authentication tokens. This segmentation allows the system to maintain design simplicity through standard interfaces while adding security only where necessary through the separate secure interface.
Solution Approach 2:
The authentication token acts as an intermediary that adds security to the standard interface without requiring customization of the hard macro itself. The token-based authentication mechanism mediates access to the secure interface, allowing standard interfaces to be used for communication while maintaining security through the intermediary authentication layer.
Data Source
AI summary
A circuit implemented as a System-on-Chip (SOC) circuit comprising a microcontroller configured to drive one or more hard macros via a respective communication interface and a shielded bus. The microcontroller configured to transmit over the shielded bus random numbers to the hard macro. The microcontroller and the hard macro configured to use these random numbers as cryptographic shared secret for authentication. The microcontroller configured to drive via the communication interface the hard macros authenticated via the random numbers.


