SoC Security Key Management via eFuse and Flash Integration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information systems rely heavily on external security chips, which increase costs and complexity in security configuration, and are vulnerable to security breaches due to external processor connections.
Innovation Solution
A system on chip (SoC) generates an asymmetric key pair, writes a private key into an electrically programmable fuse, encrypts and stores the public key, and uses these keys to secure target software information, eliminating the need for an external security chip by integrating security management within the processor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If an external security chip is used to manage security information, then security verification functions are provided, but system costs increase and configuration complexity increases
Solution Approach 1:
The patent merges the security chip's security management functions directly into the processor by integrating key generation, encryption, and verification modules within the processor's internal architecture. This eliminates the need for a separate external security chip and reduces configuration complexity while maintaining security verification capabilities.
Solution Approach 2:
The processor is designed to perform multiple functions including both general computing tasks and specialized security management operations. By making the processor universal, the system eliminates the need for dedicated security hardware, reducing overall device complexity and cost while preserving security functions.
2Reliability
If an external security chip is used, then security verification is provided, but the connection between the security chip and processor creates security vulnerabilities
Solution Approach 1:
The patent extracts the security management functions from the external security chip and relocates them entirely within the processor's internal architecture. By removing the external security chip and its vulnerable communication interfaces, the system eliminates the security vulnerabilities associated with external connections while retaining security verification capabilities.
Solution Approach 2:
The security management modules are merged with the processor's internal architecture, creating a unified secure environment. This integration removes the need for external communication interfaces between security components and the processor, thereby eliminating the security vulnerabilities present in externally-connected security systems.
3Reliability
If a security chip is purchased for security management, then security functions are implemented, but system costs increase
Solution Approach 1:
The processor is designed to serve dual purposes: general computing operations and specialized security management. By making the processor universal, the system eliminates the need to purchase separate security chips, thereby reducing system costs while maintaining comprehensive security management capabilities.
Solution Approach 2:
The patent combines security management functions with the processor's existing architecture, eliminating the need for separate security hardware purchases. This integration reduces system costs by removing the need to buy additional security chips while maintaining full security management functionality.
Data Source
AI summary
Embodiments of the present invention provide a security information configuration method, so as to reduce costs, simplify a security information configuration process, and improve security and reliability of security information configuration. The security information configuration method provided in the embodiments of the present invention includes: generating, by an SoC, an asymmetric key pair; writing a private key into an eFuse of the SoC; encrypting a public key; writing the encrypted public key into a flash memory for storage; generating first digest information according to target software information; making a signature for the first digest information, so as to obtain signature information; and writing the signature information into the flash memory. The embodiments of the present invention further provide a related security verification method and a related chip.


