Hardware Trace Data Security With Independent Session Re-Keying
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Modern microcontrollers' trace subsystems lack adequate security measures, transmitting diagnostic data in plain text over internal networks, posing risks to confidentiality and security in security-critical applications.
Innovation Solution
A hardware-based securing unit operates independently from the computing unit to authenticate and encrypt diagnostic data using session keys, changing them independently of the computing unit's operation, and optionally using pre-calculated or incrementally generated keys to prevent nonce reuse.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If trace subsystem transmits diagnostic data in plain text over internal network, then data transmission bandwidth is maximized and system complexity is minimized, but data security and confidentiality are compromised
Solution Approach 1:
A dedicated securing unit is introduced as an intermediary component between the trace subsystem and the network interface. This separate hardware module independently handles encryption and authentication of trace data before transmission, without requiring involvement from the main computing unit. The securing unit acts as a mediator that protects data confidentiality while maintaining transmission efficiency.
Solution Approach 2:
The system is divided into functionally separate components: the trace subsystem generates data, the securing unit processes and encrypts data, and the network interface transmits data. This segmentation allows the securing unit to operate independently with dedicated security functions, preventing security issues from affecting the main computing unit while enabling robust encryption without compromising bandwidth.
2Object-affected harmful factors
If debug subsystem is disabled or password-locked for security, then security risk is reduced, but diagnostic capability is lost
Solution Approach 1:
Instead of restricting access to the debug subsystem to maintain security, the invention inverts the approach by making the trace subsystem independently accessible and securing the data output instead. The trace subsystem remains fully operational without authentication requirements, while the securing unit ensures that transmitted data is encrypted, thus maintaining diagnostic capability while achieving security through a different mechanism.
3Object-affected harmful factors
If session keys are changed independently of computing unit operation, then data security is improved, but device complexity increases
Solution Approach 1:
The securing unit is designed to autonomously manage session keys without requiring control or coordination from the computing unit. It independently generates, stores, and switches session keys based on its own internal state or external triggers. This self-service capability enables frequent key changes for enhanced security while avoiding the complexity of integrating key management into the main computing unit's operation.
Solution Approach 2:
The securing unit pre-calculates and stores multiple session keys in advance, ready for immediate use. When a key change is needed, it can switch to a pre-prepared key without requiring complex real-time generation or coordination with the computing unit. This preliminary preparation of keys simplifies the key management process while maintaining high security standards.
Data Source
AI summary
Example implementations according to the present disclosure include a device for securing diagnostic data relating to the operation of a computing unit, wherein the device has an interface and a securing unit. The interface is configured to obtain the diagnostic data of the computing unit. The securing unit is formed as a hardware structure that can be operated separately from the computing unit. Furthermore, the securing unit is configured to secure the diagnostic data using session keys and to provide a change between session keys (re-keying) independently of the operation of the computing unit.


