Trusted Region Data Store Security Component

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data processing devices, especially those in IoT applications, often lack the necessary security capabilities required for secure communication and data protection, particularly in sensitive sectors like automotive, military, and aerospace, due to limited security resources and functionality.

Innovation Solution

A data processing device with a security component that partitions its data store into trusted and untrusted regions, using a security component to manage key data and generate temporary keys for secure communication, and executes trusted code upon power events or trigger signals to ensure secure operations and data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If devices are made more secure with dedicated security capabilities, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines security functionality with existing processor and memory components by implementing a processor that can execute both trusted and untrusted code and a memory system with trusted and untrusted regions. This merging approach provides security capabilities without adding separate dedicated security hardware, thus improving security reliability while avoiding the complexity increase that would result from adding independent security modules.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent segments the memory system into trusted and untrusted regions, and the processor into different code execution modes. This segmentation allows the system to maintain security by isolating sensitive operations while using existing hardware components, thereby improving security without requiring entirely new device architectures that would increase complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security resources are enhanced, then data protection is improved, but device functionality is reduced due to limited resources

Engineering Contradiction:
Improvedata protectionVSAvoiddevice functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal processor architecture that can execute both trusted and untrusted code, and a memory system that serves both security and data storage functions. This multi-functionality allows the device to provide strong data protection through trusted code execution while maintaining full device functionality, as the same hardware components serve multiple purposes rather than requiring separate dedicated security resources that would limit overall functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10956619B2Devices and method of operation thereof
Publication Date: 2021.03.23 ARM LTD
  • US10956619B2 patent drawing
  • US10956619B2 patent drawing
  • US10956619B2 patent drawing

AI summary

A device comprising: a processing element; a data store, coupled to the processing element, the data store comprising a non-volatile data store having a trusted region for trusted code and an untrusted region for untrusted code; a security component, coupled to the processing element and the data store, wherein the security component is configured to, in response to one of a power event occurring at the device and receiving a trigger signal, send a first signal to the processing element and the data store, and wherein the processing element is configured to execute trusted code in response to the first signal.