SoC ROM Partitioning for Secure Boot Without Code Download
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multimedia systems with integrated security architectures face challenges in providing adequate protection against unwanted access, as they often require complex and costly security-enabled boot up code and maintenance, especially for users with limited security requirements.
Innovation Solution
A system-on-a-chip (SoC) architecture that includes a security processor, ROM, and one-time-programmable (OTP) memory, allowing for booting without code download from external memory by partitioning the ROM into restricted and download portions, with access controlled by OTP bits, enabling secure operations and reducing maintenance needs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security management mechanisms are implemented in multimedia systems, then security protection is improved, but device complexity and maintenance cost increase
Solution Approach 1:
The ROM is divided into two distinct portions: a first portion containing code for secure boot-up and a second portion containing code for downloading security algorithms from external memory. This segmentation allows the system to provide security protection when needed while maintaining simpler boot-up code for non-secure applications, thereby resolving the contradiction between security protection and device complexity.
Solution Approach 2:
The system dynamically selects which ROM portion to access based on security requirements. The security processor can be configured to access either the first portion (for secure boot-up) or the second portion (for downloading security algorithms), allowing the system to adapt its complexity level based on the specific application needs, thus reducing unnecessary complexity for non-secure applications.
2Reliability
If security management mechanisms are implemented in multimedia systems, then security protection is improved, but maintenance cost and support requirements increase
Solution Approach 1:
By segmenting the ROM into dedicated portions for secure boot-up and for downloading security algorithms, the system separates security-related functionality from general boot-up code. This segmentation simplifies maintenance by allowing security algorithms to be updated independently from the core boot-up code, reducing the complexity and cost of maintenance for non-secure applications.
Solution Approach 2:
The code for downloading security algorithms from external memory is extracted into a separate second portion of the ROM. This extraction allows the security algorithms to be updated or modified without affecting the core boot-up code, thereby reducing maintenance costs and support requirements for systems that do not require security protection.
3Adaptability or versatility
If code download functionality is added to ROM, then adaptability is improved, but device complexity increases
Solution Approach 1:
The ROM is segmented into a first portion for secure boot-up code and a second portion for code download functionality. This segmentation adds adaptability by enabling the system to download security algorithms from external memory while keeping the core boot-up code structure simple and unchanged, thus minimizing the increase in device complexity.
Solution Approach 2:
The second portion of the ROM provides multi-functionality by enabling both secure boot-up operations and the ability to download security algorithms from external memory. This universal design allows a single ROM structure to serve multiple purposes, improving adaptability without proportionally increasing device complexity.
Data Source
AI summary
Aspects of a method and system for allowing no code download in a code download scheme are provided. A system-on-a-chip (SoC) may comprise a security processor, a ROM, and a one-time-programmable (OTP) memory. The security processor may enable fetching code from a restricted function portion of the ROM. The restricted functions may comprise code for booting up the SoC and code that prevents enabling security algorithms within the SoC. The security processor may then enable booting up of at least a portion of the SoC based on the fetched code. The remaining portion of the ROM may comprise code for downloading security code from an external memory, such as a FLASH memory, to an internal memory, such as a RAM, to boot up the SoC. Access to the restricted function portion or the remaining portion of the ROM is based on at least one bit from the OTP memory.


