IP Library Granted Patent US 12,339,975
Granted Patent B2
US 12,339,975 · App. 17/700,643 · Granted Jun 24, 2025

Security device and methods of operating a security device

Inventors: Joerg Syassen (Oberhausen, DE); Avni Bildhaiya (Deisenhofen bei Muenchen, DE); Andreas Graefe (Munich, DE); Albrecht Mayer (Deisenhofen, DE); Manuela Meier (Munich, DE); Viola Rieger (Munich, DE)
Assignee: Infineon Technologies AG
G06F21/602G06F21/70
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,339,975
App. No.
17/700,643
Filed
Mar 22, 2022
Granted
Jun 24, 2025
Kind
B2
Art Unit
2434
USPC
713/189
Abstract

A device includes a safety domain having a processing unit and a memory and is configured to provide at least one functionality and to implement one more safety measures for detecting faults. The safety domain is configured to transmit at least one alarm signal indicating one or more detected errors in response to detecting the faults. The device further includes a security domain having a processing unit and a memory and is configured to provide cryptographic services and to obtain alarm signals. The security domain is configured to perform security-related operations in a secure state in response to obtaining an alarm signal from the safety domain.

Claims (46)

1. An integrated processing device comprising:

a security domain comprising at least one processing unit and a memory and configured to provide one or more cryptographic services;

a safety domain coupled to the security domain, the safety domain comprising at least one processing unit and a memory and configured to execute one or more processes, control one or more peripherals, and provide one more safety measures to detect one or more hardware faults, wherein the safety domain operates continuously or substantially continuously according to a safety related standard, further wherein the security domain operates independently of the safety domain;

wherein the safety domain is configured to, in response to detecting a hardware fault in a component of the safety domain,

perform a hardware-related remedial action on one or more components of the safety domain; and

after initiation of the hardware-related remedial action, transmit an alarm signal indicating detection of hardware faults to the security domain; and

wherein the security domain is configured to, in response to the alarm signal, perform one or more cryptographic service-related security operations.

2. The integrated processing device of claim 1 , wherein the security domain is physically separate from the safety domain.

3. The integrated processing device of claim 1 , wherein the one or more cryptographic service-related security operations comprise deleting cryptographic keys stored in the security domain.

4. The integrated processing device of claim 1 , wherein the one or more cryptographic service-related security operations comprise sending out a security interrupt signal.

5. The integrated processing device of claim 1 , wherein the one or more cryptographic service-related security operations comprise resetting one or more settings of the security domain.

6. The integrated processing device of claim 1 , wherein the one or more cryptographic service-related security operations comprise locking one or more external interfaces of the security domain.

7. The integrated processing device of claim 1 , wherein the one or more cryptographic service-related security operations comprise delaying performance of one or more previously scheduled cryptographic service-related actions for at least a predefined period of time.

8. The integrated processing device of claim 1 , further comprising

a first chip comprising the safety domain; and

a second chip comprising the security domain, the second chip being separate from the first chip.

9. The integrated processing device of claim 1 , wherein the safety domain and the security domain are located on a same semiconductor substrate.

10. The integrated processing device of claim 1 , wherein

the integrated processing device is a semiconductor integrated circuit chip comprising a plurality of processor cores,

the safety domain comprises one or more first cores of the plurality of processor cores, and

the security domain comprises one or more second cores of the plurality of processor cores, the first cores being separate from the second cores.

11. The integrated processing device claim 1 , further comprising a communication interface, wherein the communication interface is coupled to the safety domain and to the security domain.

12. The integrated processing device of claim 1 , wherein the safety domain comprises one or more application specific peripherals.

13. The integrated processing device of claim 1 , wherein the security domain comprises at least one cryptographic accelerator or random number generator.

14. The integrated processing device of claim 1 , wherein the safety domain is configured to detect one or more hardware faults by obtaining sensor data and detecting operating condition violations in the safety domain from the obtained sensor data.

15. The integrated processing device of claim 14 , wherein the sensor data comprises sensor data comprises temperature data, supply voltage data, and/or clock data.

16. The integrated processing device of claim 1 , wherein the safety domain is configured to control a motor.

17. The integrated processing device of claim 1 , wherein the safety domain is configured to control one or more brakes of a vehicle.

18. The integrated processing device of claim 1 , is configured to extract data from one or more radar measurements obtained by the integrated processing device.

19. The integrated processing device of claim 1 , wherein the hardware-related remedial action comprises controlling the at least one processing unit of the safety domain to operate in a lockstep mode.

20. A security domain system configured to provide one or more cryptographic services, comprising:

a memory; and

at least one processing unit configured to

receive an alarm signal from a safety domain system that detects hardware faults and operates continuously or substantially continuously according to a safety related standard, the alarm signal indicative of the safety domain system initiating remedial action in response to a hardware fault occurring in the safety domain system, wherein the security domain system operates independently of the safety domain system, and

in response to the alarm signal, perform one or more cryptographic service-related operations in at least one secure state.

21. The security domain system of claim 20 , wherein the one or more cryptographic service-related operations comprise deleting cryptographic keys stored in the security domain system.

22. The security domain system of claim 20 , wherein the one or more cryptographic service-related operations comprise sending out a security interrupt signal.

23. The security domain system of claim 20 , wherein the one or more cryptographic service-related operations comprise resetting one or more settings of the security domain system.

24. The security domain system of claim 20 , wherein the one or more cryptographic service-related operations comprise locking one or more external interfaces of the security domain system.

25. An integrated processing device comprising:

a security domain comprising at least one processing unit and a memory and configured to provide one or more cryptographic services;

a safety domain coupled to the security domain, the safety domain comprising at least one processing unit and a memory and configured to execute one or more processes, control one or more peripherals, and provide one more safety measures to detect one or more hardware faults, wherein the safety domain operates continuously or substantially continuously according to a safety related standard, further wherein the security domain is physically separate from the safety domain;

wherein the safety domain is configured to, in response to detecting a hardware fault in a component of the safety domain,

perform a hardware-related remedial action on one or more components of the safety domain; and

after initiation of the hardware-related remedial action, transmit an alarm signal indicating detection of hardware faults to the security domain; and

wherein the security domain is configured to, in response to the alarm signal, perform one or more cryptographic service-related security operations.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 19, 2022
From: SYASSEN, JOERG; BILDHAIYA, AVNI; GRAEFE, ANDREAS; MAYER, ALBRECHT; MEIER, MANUELA; RIEGER, VIOLA
To: INFINEON TECHNOLOGIES AG
Reel/Frame 059959/0319 →
Priority Claims (1)
DE 10 2021 107 364.2 · Mar 24, 2021 · national
Continuity (1)
Related Publication 20220309169A1 · Sep 29, 2022
References Cited (11)
US 5165497A · Chi · 1992 [cited by examiner]
US 10721258B2 · Sood · 2020 [cited by examiner]
US 11644834B2 · Ditty · 2023 [cited by examiner]
US 11972033B2 · Johnson · 2024 [cited by examiner]
US 20100332851A1 · Priel et al. · 2010 [cited by applicant]
US 20150185268A1 · Falk · 2015 [cited by applicant]
US 20170344438A1 · Bilgiday et al. · 2017 [cited by applicant]
US 20200218808A1 · Hershman · 2020 [cited by applicant]
US 20210409210A1 · Krummel · 2021 [cited by examiner]
DE 102006005053A1 · 2007 [cited by applicant]
DE 102013214398A1 · 2015 [cited by applicant]