SOC Secure Processor Power Domain Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of system on a chip (SOC) devices is compromised during power up and down operations in low power modes, as they are vulnerable to attacks due to the need to balance power efficiency and functionality in mobile devices.

Innovation Solution

Incorporating an always-on component that remains powered even when other parts of the SOC are powered off, allowing secure processor state to be stored in encrypted form and retrieved upon power-up, thereby simplifying recovery and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of energy

If the secure processor is powered down to eliminate leakage current losses, then energy consumption is reduced, but security is compromised during power up/power down operations

Engineering Contradiction:
Improveleakage current lossesVSAvoidsecurity
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The system is divided into two independent power domains: a main power domain containing the secure processor that can be powered down, and an always-on power domain containing the always-on component that remains powered. This segmentation allows the secure processor to be powered down for energy savings while the always-on component maintains security functions continuously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The always-on component performs preliminary security actions by maintaining security state and cryptographic context in an encrypted security state storage device even when the secure processor is powered down. This preliminary preparation ensures that security is not compromised during power transitions, as the always-on component can quickly restore security functions without exposing sensitive data during the vulnerable power-up phase.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the secure processor is powered up and down repeatedly during standby mode, then standby functionality is maintained, but security vulnerabilities increase

Engineering Contradiction:
Improvestandby functionalityVSAvoidattack vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The always-on component acts as an intermediary that bridges the secure processor and the security state storage device. It maintains the security context and cryptographic state independently, allowing the secure processor to be powered down during standby without exposing security vulnerabilities. The always-on component mediates security operations, eliminating the need for repeated power cycles while maintaining both standby functionality and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Use of energy by moving object

If the SOC is completely powered off to conserve energy, then power efficiency is improved, but standby functionality is lost

Engineering Contradiction:
Improvepower efficiencyVSAvoidstandby functionality
Core Design Contradiction:
Use of energy by moving objectVSAdaptability or versatility

Solution Approach 1:

The SOC is segmented into multiple power domains with different power states. The main power domain can be completely powered off for maximum energy savings, while the always-on power domain remains active to provide essential standby functionality such as listening for phone calls, checking for alarms, and detecting movement. This segmentation enables the system to achieve high power efficiency while maintaining necessary standby capabilities.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9479331B2Managing security in a system on a chip (SOC) that powers down a secure processor
Publication Date: 2016.10.25 APPLE INC
  • US9479331B2 patent drawing
  • US9479331B2 patent drawing
  • US9479331B2 patent drawing

AI summary

An SOC includes a secure processor and an always-on component. The always-on component may remain powered even during times that other parts of the SOC are powered off. Particularly, the secure processor and related circuitry may be powered off, while various state for the secure processor may be stored in memory in an encrypted form. Certain state may be stored in the always-on component. When the secure processor is powered on again, the secure processor may check for the state in the always-on component. If the state is found, the secure processor may retrieve the state and use the state to access the encrypted memory state.