SoC Secure Controller Isolating Memory Data

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System on chip (SoC) devices face limitations in internal memory capacity, necessitating external memory integration, while requiring secure access and protection of security data from potential attacks.

Innovation Solution

Incorporating a secure module with a secure controller, nonvolatile memories, and an encryption/decryption module to monitor log data, store secure parameters, and encrypt/decrypt data transmitted between the SoC and external devices, ensuring secure access and protection against security attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If external memory devices are coupled to compensate for limited internal memory size, then memory capacity is improved, but security risk increases due to potential attacks on data transmission and storage

Engineering Contradiction:
Improvememory capacityVSAvoidsecurity risk
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The system divides memory into separate secure and non-secure regions. The secure memory is dedicated to storing security data and is isolated from the host controller and shared memory, creating a segmented architecture that protects sensitive information while allowing external memory expansion for non-critical data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An encryption/decryption module acts as an intermediary between the secure memory and the host controller. This intermediary component encrypts data before storing it in secure memory and decrypts it during retrieval, providing security protection without preventing the memory expansion functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a security element is added to provide security functions, then security level is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity levelVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security element is merged with the memory controller functionality. The secure memory, encryption/decryption module, and secure controller are integrated into a unified secure memory controller unit that works alongside the host controller, reducing overall system complexity compared to separate security and memory management components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure controller serves multiple functions: it manages the secure memory, controls the encryption/decryption operations, monitors for security attacks through log analysis, and interfaces with the host controller. This multi-functional design reduces the number of separate components needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If nonvolatile memory is used for secure parameter storage, then security reliability is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Secure parameters such as encryption keys are pre-generated and stored in the nonvolatile secure memory during the manufacturing process. This preliminary action ensures that security credentials are already in place before the device is deployed, simplifying the manufacturing process compared to implementing complex key generation and distribution systems.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11244066B2System on chip
Publication Date: 2022.02.08 SAMSUNG ELECTRONICS CO LTD
  • US11244066B2 patent drawing
  • US11244066B2 patent drawing
  • US11244066B2 patent drawing

AI summary

A system on chip includes a host controller and a secure controller for securing communication between the system on chip and external devices accessing a memory controlled by a memory and an encryption/decryption module for encrypting and decrypting the data.