SoC Security Plugin Modular Interconnect Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

SoC platforms face challenges in integrating security components due to inconsistent security implementations, diverse fabrics, and the need for additional resources and time, leading to delayed product launches.

Innovation Solution

A modular and scalable micro-architecture security plugin with a standard interface for cryptographic engines is integrated into the SoC interconnect fabric, allowing selection of cryptographic engines based on security and manufacturing goals without redesigning other components, ensuring secure communication across all SoC components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security components are integrated into SoC platforms with diverse fabrics and inconsistent security implementations, then security coverage is improved, but integration complexity and resource requirements increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidintegration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security plugin is segmented into distinct functional modules including a security engine, a control unit, and an interface unit. Each module performs a specific function (encryption/decryption, key management, message routing) allowing independent design, verification, and integration into different SoC fabrics without requiring complete redesign of the entire security subsystem.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security plugin employs a universal interface design that can communicate with multiple types of SoC fabrics and components through standardized protocols. The control unit can manage different cryptographic algorithms and the interface unit adapts to various fabric architectures, enabling a single security plugin design to serve multiple security requirements across diverse SoC platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If custom security implementations are developed for each SoC platform, then security requirements are met, but development time and resource requirements increase

Engineering Contradiction:
Improvesecurity requirements complianceVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security plugin is designed and verified as a complete, pre-integrated security subsystem before SoC platform integration. The security engine, control unit, and interface unit are configured and tested together in advance, allowing the entire security implementation to be dropped into the target SoC platform as a ready-made solution rather than being developed from scratch for each platform.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security plugin uses configurable parameters and registers that can be programmed to match different security requirements of various SoC platforms. The control unit can be configured through register settings to enable different cryptographic algorithms, key lengths, and security protocols, allowing a single hardware design to adapt to multiple security standards without physical redesign.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive security is provided for all interconnect messages, then security coverage is improved, but performance overhead increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidmessage throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security plugin applies security processing selectively rather than uniformly to all messages. The control unit can be configured to encrypt only specific message types, routes, or data classes that require security protection, while allowing non-sensitive communications to pass through the interconnect without encryption overhead, thus maintaining security coverage for critical communications while preserving overall system throughput.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12093431B2Security plugin for a system-on-a-chip platform
Publication Date: 2024.09.17 INTEL CORP
  • US12093431B2 patent drawing
  • US12093431B2 patent drawing
  • US12093431B2 patent drawing

AI summary

Systems and techniques for a System-on-a-Chip (SoC) security plugin are described herein. A component message may be received at an interconnect endpoint from an SoC component. The interconnect endpoint may pass the component message to a security component via a security interlink. The security component may secure the component message, using a cryptographic engine, to create a secured message. The secured message is delivered back to the interconnect endpoint via the security interlink and transmitted across the interconnect by the interconnect endpoint.