SoC Security Circuit Selective Debug Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current system-on-chip technologies lack the ability to monitor and debug complex systems during operation without compromising operational safety, as existing debug facilities are often invasive and require additional components, and can cause safety issues when activated during device usage.
Innovation Solution
A system-on-chip with a hardware security module that enables selective read-only or read-write access to control circuit areas based on authenticated certificates, allowing for secure and flexible monitoring and debugging without additional hardware, and maintaining functionality even when the main control system is stopped.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Difficulty of detecting and measuring
If debug facilities are integrated into the system-on-chip, then diagnostic capability is improved, but operational safety deteriorates due to invasive access during device usage
Solution Approach 1:
The system is divided into a main control system and a separate hardware security module (HSM). The HSM contains a separate control circuit with authenticated access to debug interfaces, physically and logically separating diagnostic functions from the main control system. This segmentation allows debugging without compromising the safety-critical main system's operational integrity.
Solution Approach 2:
The hardware security module acts as an intermediary between external diagnostic tools and the main control system. It provides authenticated access to debug interfaces while maintaining isolation from safety-critical control circuits. The HSM verifies certificates and manages access rights, serving as a secure mediator that enables diagnostics without direct invasive access to the main system.
2Difficulty of detecting and measuring
If additional hardware components are added for debugging, then diagnostic functionality is improved, but device complexity increases
Solution Approach 1:
The debug interface and authentication logic are merged into the existing hardware security module, which is already present in the system-on-chip for security purposes. This consolidation eliminates the need for separate additional debugging hardware components, reducing overall device complexity while maintaining comprehensive diagnostic functionality.
Solution Approach 2:
The hardware security module is designed to serve multiple functions: it handles security operations, manages authenticated access, and provides debug interface control. This multi-functionality eliminates the need for dedicated separate debugging hardware, reducing device complexity while enabling comprehensive diagnostic capabilities.
3Ease of repair
If read-write access is enabled for debugging, then error correction capability is improved, but security risks increase
Solution Approach 1:
The access rights to control circuit areas are dynamically adjusted based on authentication results and diagnostic needs. The hardware security module can grant read-only access for monitoring, read-write access for error correction, or revoke access entirely. This dynamic access control enables flexible error correction while maintaining security through certificate-based authentication and configurable access levels.
Solution Approach 2:
The system changes the access parameter (read-only vs. read-write) based on authentication credentials and diagnostic requirements. Different certificates can grant different access levels, allowing full read-write access for authorized error correction while restricting access for routine monitoring. This parameter change approach enables secure error correction capability while managing security risks through fine-grained access control.
Data Source
AI summary
In different example embodiments, a system-on-chip is provided. The system-on-chip can have a control circuit with a plurality of control circuit areas, wherein the control circuit is configured to control a device, a security circuit which has a separately secured key memory and a hardware accelerator for cryptographic operations, wherein the security circuit is configured to electively enable either a read-only access or a read and write access to at least one of the control circuit areas, wherein the security circuit is furthermore configured to provide a communication path by means of the key memory and the hardware accelerator for the secured communication with a diagnostic system disposed outside the security circuit, to make the selection between the read access and the read and write access to the at least one selected area of the control circuit depending on a certificate supplied to the security circuit and authenticated by means of information stored in the key memory, and to execute the read access or the read and write access.


