IP Library Granted Patent US 12,475,261
Granted Patent B2
US 12,475,261 · App. 17/961,693 · Granted Nov 18, 2025

Integrated circuit

Inventor: Mohamed Soubhi (Dusseldorf, DE)
Assignee: Renesas Electronics Corporation
G06F21/72G06F12/1408G06F15/7842
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,475,261
App. No.
17/961,693
Granted
Nov 18, 2025
Kind
B2
Abstract

An integrated circuit includes a safety processor and a secure computing module including a secure processor, first and second cryptographic units for encrypting and decrypting data, and first and second data transfer units for transferring data between a memory and the first and second cryptographic units respectively. The first cryptographic unit and the first data transfer unit provide a first cryptographic data handling system and the second cryptographic unit and the second data transfer unit provide a second cryptographic data handling system. The secure computing module includes selector circuitry for selectively coupling and uncoupling the first and second cryptographic units in response to control signals from a switch. In a first mode, the first and second cryptographic data handling systems are uncoupled and operable independently of each other. In a second mode, the first and second cryptographic data handling system are coupled and operable together to provide hardware redundancy.

Claims (58)

1 . An integrated circuit comprising:

a safety processor;

a memory;

a secure computing module comprising:

a secure processor;

first and second cryptographic units for encrypting and decrypting data in the memory; and

first and second data transfer units for transferring data between the memory and the first and second cryptographic units respectively,

wherein the first cryptographic unit and the first data transfer unit provide a first cryptographic data handling system, and the second cryptographic unit and the second data transfer unit provide a second cryptographic data handling system; and

a switch,

wherein the secure computing module further comprises:

selector circuitry for selectively coupling and uncoupling the first and second cryptographic data handling systems in response to control signals from the switch, such that:

in a first mode, the first and second cryptographic data handling systems are uncoupled and operable independently of each other; and

in a second mode, the first and second cryptographic data handling system are coupled and operable together to provide hardware redundancy,

wherein the secure computing module further comprises a first cryptographic signature or hash engine and a second cryptographic signature or hash engine, and

wherein:

the first cryptographic data handling system and the first cryptographic signature or hash engine are operable to process a first code block in a booting process; and

the second cryptographic data handling system and the second cryptographic signature or hash engine are operable to process a second code block during the booting process.

2 . The integrated circuit of claim 1 , wherein:

in the first mode, the first cryptographic data handling system is operable to process first data stored in the memory and the second cryptographic data handling system is operable to process second, different data stored the memory, simultaneously; and

in the second mode, the first and second cryptographic data handling systems are operable to process the first and second data sequentially.

3 . The integrated circuit of claim 1 , wherein, the safety processor is configured, in response to receiving or transmitting encrypted safety data, to send a request to the switch to cause the secure computing module to switch from the first mode to the second mode.

4 . The integrated circuit of claim 1 ,

wherein the switch comprises state monitor,

wherein the selector circuitry comprises a set of selectors, and

wherein each selector in the set of selectors is arranged to communicate its state to the state monitor and wherein the switch is configured to determine the respective states of the selectors in the set of selectors and, upon determining the respective states are correct, to switch between a first state and a second state.

5 . The integrated circuit of claim 1 , further comprising:

a communications controller for receiving and transmitting data from a bus,

wherein the communications controller is operable to:

receive received data and to store the received data in the memory; and

retrieve transmit data from the memory and to transmit the transmit data.

6 . The integrated circuit of claim 1 , wherein the switch comprises:

a scheduler; and

a timer,

wherein the scheduler is configured:

in response to the timer reaching a first pre-defined value, to cause the secure computing module to switch from the first mode to the second mode, and

in response to the time reaching a second pre-defined value, to cause the secure computing module to switch from the second mode to the first mode.

7 . The integrated circuit of claim 1 , further comprising:

an error module,

wherein the switch is configured to monitor states of selectors in the selector circuitry and, in response to a given selector or the switch determining that the given selector is in an erroneous state, the given selector and/or switch sending an error signal to the error module.

8 . The integrated circuit of claim 1 , wherein the hardware redundancy is sufficient to support Automotive Safety Integrity Level (ASIL) level D.

9 . The integrated circuit of claim 1 , wherein the integrated circuit is a microcontroller or a system-on-a-chip.

10 . A vehicle comprising:

a bus; and

at least two nodes arranged to communicate via the bus, each node comprising the integrated circuit of claim 1 .

11 . A switching method comprising:

selectively coupling and uncoupling, by a secure computing module, first and second cryptographic data handling systems, wherein the first cryptographic data handling system comprises a first cryptographic unit and a first data transfer unit, and the second cryptographic data handling system comprises a second cryptographic unit and a second data transfer unit, such that:

in a first mode, the first and second cryptographic data handling systems are uncoupled and operable independently of each other; and

in a second mode, the first and second cryptographic data handling system are coupled and operable together to provide hardware redundancy,

wherein the secure computing module comprises a first cryptographic signature or hash engine and a second cryptographic signature or hash engine, and

wherein:

the first cryptographic data handling system and the first cryptographic signature or hash engine are operable to process a first code block in a booting process; and

the second cryptographic data handling system and the second cryptographic signature or hash engine are operable to process a second code block during the booting process.

12 . The switching method of claim 11 , comprising:

coupling the first and second cryptographic data handling systems in response to a request from a safety processor; and

later, uncoupling the first and second cryptographic data handling systems.

13 . The switching method of claim 11 , comprising:

coupling the first and second cryptographic data handling systems in response to a timer value reaching a predetermined timer value threshold; and

later, uncoupling the first and second cryptographic data handling systems.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2022
From: SOUBHI, MOHAMED
To: RENESAS ELECTRONICS CORPORATION
Reel/Frame 061344/0490 →
Priority Claims (1)
EP 21203520 · Oct 19, 2021 · regional
Continuity (1)
Related Publication 20230119255A1 · Apr 20, 2023
References Cited (8)
US 11238166B2 · Schramm · 2022 [cited by examiner]
US 20100287443A1 · Rohleder · 2010 [cited by examiner]
US 20100318811A1 · Motoyama · 2010 [cited by examiner]
US 20110191599A1 · Chou · 2011 [cited by examiner]
US 20190356468A1 · Zeh · 2019 [cited by examiner]
US 20200117814A1 · Ito · 2020 [cited by examiner]
US 20200192742A1 · Boettcher et al. · 2020 [cited by applicant]
Extended European Search Report dated Mar. 18, 2022 received in European Patent Application No. EP 21203520.8. [cited by applicant]