SoC Security Plugin Modular Interconnect Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
SoC platforms face challenges in integrating security components due to inconsistent security implementations, diverse fabrics, and the need for additional resources and time, leading to delayed product launches.
Innovation Solution
A modular and scalable micro-architecture security plugin with a standard interface for cryptographic engines is integrated into the SoC interconnect fabric, allowing selection of cryptographic engines based on security and manufacturing goals without redesigning other components, ensuring secure communication across all SoC components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security components are integrated into SoC platforms with diverse fabrics and inconsistent security implementations, then security coverage is improved, but integration complexity and resource requirements increase
Solution Approach 1:
The security plugin is segmented into distinct functional modules including a security engine, a control unit, and an interface unit. Each module performs a specific function (encryption/decryption, key management, message routing) allowing independent design, verification, and integration into different SoC fabrics without requiring complete redesign of the entire security subsystem.
Solution Approach 2:
The security plugin employs a universal interface design that can communicate with multiple types of SoC fabrics and components through standardized protocols. The control unit can manage different cryptographic algorithms and the interface unit adapts to various fabric architectures, enabling a single security plugin design to serve multiple security requirements across diverse SoC platforms.
2Reliability
If custom security implementations are developed for each SoC platform, then security requirements are met, but development time and resource requirements increase
Solution Approach 1:
The security plugin is designed and verified as a complete, pre-integrated security subsystem before SoC platform integration. The security engine, control unit, and interface unit are configured and tested together in advance, allowing the entire security implementation to be dropped into the target SoC platform as a ready-made solution rather than being developed from scratch for each platform.
Solution Approach 2:
The security plugin uses configurable parameters and registers that can be programmed to match different security requirements of various SoC platforms. The control unit can be configured through register settings to enable different cryptographic algorithms, key lengths, and security protocols, allowing a single hardware design to adapt to multiple security standards without physical redesign.
3Reliability
If comprehensive security is provided for all interconnect messages, then security coverage is improved, but performance overhead increases
Solution Approach 1:
The security plugin applies security processing selectively rather than uniformly to all messages. The control unit can be configured to encrypt only specific message types, routes, or data classes that require security protection, while allowing non-sensitive communications to pass through the interconnect without encryption overhead, thus maintaining security coverage for critical communications while preserving overall system throughput.
Data Source
AI summary
Systems and techniques for a System-on-a-Chip (SoC) security plugin are described herein. A component message may be received at an interconnect endpoint from an SoC component. The interconnect endpoint may pass the component message to a security component via a security interlink. The security component may secure the component message, using a cryptographic engine, to create a secured message. The secured message is delivered back to the interconnect endpoint via the security interlink and transmitted across the interconnect by the interconnect endpoint.


