SoC Validation Module Security Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System-on-chip (SoC) security is vulnerable due to exposed interfaces that can be exploited for unauthorized access to internal components and data, lacking effective management of security features and access control.

Innovation Solution

Incorporating a validation module within the SoC that manages security certificates using hardware identifiers and keys to control access to security features, enabling secure access control settings through unique identifiers, expiration times, and cryptographic signatures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If security interfaces are exposed for testing and evaluation, then developers and manufacturers can access and test device functionality, but malicious users can exploit these interfaces to obtain unauthorized access to internal components and data

Engineering Contradiction:
Improveaccessibility for testing and evaluationVSAvoidvulnerability to unauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

A validation module is introduced as an intermediary between the exposed security interfaces and the internal security features. This module verifies security certificates presented through the interfaces before allowing access to any security features or internal components. The certificate verification process acts as a mediator that enables legitimate testing and evaluation while blocking unauthorized access attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Security certificates are pre-configured with hardware identifiers and access control settings before the device is deployed. These certificates establish the rules for access control in advance, allowing the validation module to automatically enforce security policies without requiring real-time human intervention. The preliminary configuration of certificates enables seamless secure access control.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If security certificates manage access to multiple security features, then granular control over security settings is achieved, but the system complexity increases due to certificate management and verification processes

Engineering Contradiction:
Improvegranular control over security featuresVSAvoidcertificate management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

Security certificates are designed as universal credentials that can manage access to multiple different security features simultaneously. Each certificate contains hardware identifiers and access control settings that can apply to various security features across different hardware modules. This multi-functional approach allows a single certificate to control multiple security aspects, reducing the number of separate management mechanisms needed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The validation module combines multiple security verification functions into a single component. It integrates hardware identifier verification, certificate authenticity validation, and access control setting enforcement all within one module. This consolidation reduces system complexity by merging what could be separate complex subsystems into a unified validation mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9716708B2Security certificates for system-on-chip security
Publication Date: 2017.07.25 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9716708B2 patent drawing
  • US9716708B2 patent drawing
  • US9716708B2 patent drawing

AI summary

A system-on-chip (SoC) includes multiple hardware modules that are implemented on a substrate. The hardware modules include a plurality of hardware and software security features and the SoC provides one or more external interfaces for accessing the security features. A validation module, implemented in the boot code of the SoC for example, manages security certificates to control access to the plurality of security features. Each security certificate includes one or more unique identifiers corresponding to one or more hardware modules in the SoC and access control settings for one or more security features of the one or more hardware modules. The security certificate additionally includes a certificate signature signed by a secure key.