SoC Secure Element Dynamic Encryption Seed Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
System on chip (SoC) applications face limitations in security and capacity due to internal memory constraints, necessitating enhanced security measures and expanded application capabilities while protecting against external attacks.
Innovation Solution
Implementing a system on chip with secure element circuitry that dynamically changes encryption seeds based on memory location and time variations, utilizing external memory for secure data storage and processing, and employing hardware-level encryption and decryption methods to enhance data integrity and confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If internal memory capacity is increased to expand application capabilities, then application capacity is improved, but chip area and cost increase
Solution Approach 1:
The patent divides the memory system into internal memory (for critical security data) and external memory (for expandable storage), connected through a secure interface. This segmentation allows the SoC to access larger total memory capacity without proportionally increasing chip area, as the external memory is located off-chip.
Solution Approach 2:
The patent implements a nested security architecture where the secure element is embedded within the SoC structure, providing hardware-level security for data stored in both internal and external memory. The secure element acts as a protective layer that can be integrated into the existing SoC design without significantly increasing overall chip area.
2Quantity of substance
If external memory is used to expand application capacity, then application capacity is improved, but security against external attacks deteriorates
Solution Approach 1:
The patent introduces a secure element as an intermediary between the SoC and external memory. This secure element hardware module manages encryption keys and performs cryptographic operations, acting as a trusted mediator that protects data stored in external memory from external attacks while allowing the SoC to utilize the expanded storage capacity.
Solution Approach 2:
The patent dynamically changes encryption parameters (such as initialization vectors and nonces) based on memory location and time variation. This parameter changing approach ensures that even if external memory is compromised, the security protection adapts to different access patterns and time points, maintaining security while utilizing external storage.
3Ease of manufacture
If static encryption keys are used for data protection, then implementation simplicity is improved, but data integrity and security deteriorate
Solution Approach 1:
The patent transitions from static encryption keys to dynamic encryption parameters that change based on memory location and time. The secure element generates and manages these dynamic parameters, providing enhanced data integrity and security while maintaining relatively simple implementation through hardware-based key management.
Solution Approach 2:
The secure element performs self-service by automatically generating and managing encryption keys and parameters without requiring external intervention. This self-managing capability provides strong data integrity protection while keeping the system implementation simple, as the security functions are autonomously handled by the secure element hardware.
4Reliability
If hardware-level encryption is implemented to enhance security, then security capability is improved, but device complexity increases
Solution Approach 1:
The secure element serves as a dedicated intermediary hardware module that handles all encryption and decryption operations. By isolating these security functions in a separate dedicated component, the overall system complexity is managed effectively while achieving high security capability, as the secure element can be integrated into the SoC without significantly increasing overall system complexity.
Data Source
AI summary
An System on Chip (SoC) including a secure element is provided. A method of the SoC comprises generating a random number when power is turned on, generating a seed table according to the random number on the basis of a seed table operation policy, masking a first data with a first data seed value corresponding to a target address in the seed table, encrypting the masked first data with a first type first encryption key in the seed table and writing the first encrypted first data to the target address of an external memory, wherein one of the data seed value or the first type first encryption key changes dynamically.


