SoC On-the-Fly Decryption Circuit for Secure Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional SoC architectures face challenges in data protection due to high access latency and key management complexity, leading to performance deterioration and increased management costs during mass production, as they rely on complex encryption and decryption algorithms and require precise key matching between SoC chips and non-volatile memories.
Innovation Solution
The proposed SoC architecture incorporates a timer, a key bank with initial and main keys, and an on-the-fly decryption circuit operating in multiple modes, allowing for a warm reset and changing storage formats from initial to operation mode, enabling secure and efficient data protection without embedded flash memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex encryption and decryption algorithms are used in the on-the-fly decryption circuit, then data security is improved, but access latency increases and performance deteriorates
Solution Approach 1:
The encryption/decryption process is segmented into two distinct phases: an initial boot code phase that runs once during first power-on to configure security parameters, and a normal operation phase that executes encrypted program code. This segmentation allows the system to establish secure encryption keys and formats initially, then maintain security while optimizing performance during normal operation without repeated complex key setup overhead.
Solution Approach 2:
The initial boot code performs preliminary actions by establishing encryption keys, selecting encryption algorithms, and configuring the storage format before the system enters normal operation. This preliminary configuration stores security parameters in the non-volatile memory, so that during normal operation, the system can efficiently decrypt and execute code without repeatedly performing complex key generation and algorithm selection, thus reducing access latency while maintaining security.
2Reliability
If precise key matching between SoC chips and non-volatile memories is required, then data protection is improved, but management complexity and costs increase during mass production
Solution Approach 1:
The system implements self-service key management through the initial boot code that automatically generates encryption keys and configures encryption parameters when the system is first powered on. The SoC chip autonomously selects encryption algorithms, generates key pairs, and configures the non-volatile memory with the appropriate encryption format without requiring external intervention or manual key matching during assembly. This self-configuration capability eliminates the need for complex key management processes during mass production while ensuring each device has unique security credentials.
3Productivity
If the storage format is changed from initial to operation mode, then efficient data processing is achieved, but system complexity increases
Solution Approach 1:
The storage format is designed to be dynamic, automatically transitioning from an initial format (suitable for the initial boot code) to an operation format (optimized for encrypted program code execution). The system detects the current state and automatically adjusts the storage format based on the execution phase, allowing efficient data processing in each mode while managing complexity through automated format selection rather than requiring manual configuration or multiple static formats.
Data Source
AI summary
An SoC architecture includes a non-volatile memory and an SoC chip. The SoC chip is connected with the non-volatile memory. The SoC chip includes a central processing unit, a volatile memory, a system bus, an on-the-fly decryption circuit, a memory interface, a timer and a key bank. The on-the-fly decryption circuit is connected with the key bank. The on-the-fly decryption circuit performs an encryption operation or a decryption operation according to plural keys in the key bank. After the SoC architecture is powered on, if the timer is not disabled and the timer has counted time for a specified time period, the central processing unit is subjected to a warm reset, and a storage format in the non-volatile memory is changed from an initial format to an operation format by the central processing unit.


