SoC On-the-Fly Decryption Circuit for Secure Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional SoC architectures face challenges in data protection due to high access latency and key management complexity, leading to performance deterioration and increased management costs during mass production, as they rely on complex encryption and decryption algorithms and require precise key matching between SoC chips and non-volatile memories.

Innovation Solution

The proposed SoC architecture incorporates a timer, a key bank with initial and main keys, and an on-the-fly decryption circuit operating in multiple modes, allowing for a warm reset and changing storage formats from initial to operation mode, enabling secure and efficient data protection without embedded flash memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If complex encryption and decryption algorithms are used in the on-the-fly decryption circuit, then data security is improved, but access latency increases and performance deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidaccess latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The encryption/decryption process is segmented into two distinct phases: an initial boot code phase that runs once during first power-on to configure security parameters, and a normal operation phase that executes encrypted program code. This segmentation allows the system to establish secure encryption keys and formats initially, then maintain security while optimizing performance during normal operation without repeated complex key setup overhead.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The initial boot code performs preliminary actions by establishing encryption keys, selecting encryption algorithms, and configuring the storage format before the system enters normal operation. This preliminary configuration stores security parameters in the non-volatile memory, so that during normal operation, the system can efficiently decrypt and execute code without repeatedly performing complex key generation and algorithm selection, thus reducing access latency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If precise key matching between SoC chips and non-volatile memories is required, then data protection is improved, but management complexity and costs increase during mass production

Engineering Contradiction:
Improvedata protectionVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service key management through the initial boot code that automatically generates encryption keys and configures encryption parameters when the system is first powered on. The SoC chip autonomously selects encryption algorithms, generates key pairs, and configures the non-volatile memory with the appropriate encryption format without requiring external intervention or manual key matching during assembly. This self-configuration capability eliminates the need for complex key management processes during mass production while ensuring each device has unique security credentials.

Inventive Principle:
Principle #25Self-service

3Productivity

If the storage format is changed from initial to operation mode, then efficient data processing is achieved, but system complexity increases

Engineering Contradiction:
Improvedata processing efficiencyVSAvoidstorage format management
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The storage format is designed to be dynamic, automatically transitioning from an initial format (suitable for the initial boot code) to an operation format (optimized for encrypted program code execution). The system detects the current state and automatically adjusts the storage format based on the execution phase, allowing efficient data processing in each mode while managing complexity through automated format selection rather than requiring manual configuration or multiple static formats.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12124618B2SoC architecture and data protection method thereof
Publication Date: 2024.10.22 FARADAY TECH CORP
  • US12124618B2 patent drawing
  • US12124618B2 patent drawing
  • US12124618B2 patent drawing

AI summary

An SoC architecture includes a non-volatile memory and an SoC chip. The SoC chip is connected with the non-volatile memory. The SoC chip includes a central processing unit, a volatile memory, a system bus, an on-the-fly decryption circuit, a memory interface, a timer and a key bank. The on-the-fly decryption circuit is connected with the key bank. The on-the-fly decryption circuit performs an encryption operation or a decryption operation according to plural keys in the key bank. After the SoC architecture is powered on, if the timer is not disabled and the timer has counted time for a specified time period, the central processing unit is subjected to a warm reset, and a storage format in the non-volatile memory is changed from an initial format to an operation format by the central processing unit.