IP Library › Granted Patent US 11,461,475
Granted Patent B2
US 11,461,475 · App. 16/815,541 · Granted Oct 4, 2022

Electronic device including secure integrated circuit

Inventors: Bumhan Kim (Suwon-si, KR); Sunjune Kong (Suwon-si, KR); Seongjin Cho (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
G06F21/602G06F7/588G06F12/1441G06F15/7821H01L23/576H04L9/0869G06F2212/1052
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,461,475
App. No.
16/815,541
Granted
Oct 4, 2022
Kind
B2
Abstract

An electronic device including a secure Integrated Circuit (IC) is provided. The electronic device includes a secure IC configured as a System-on-Chip (SoC) and configured to provide a general environment and a security environment, wherein the secure IC includes a main processor configured to operate in the general environment, a secure processor configured to operate in the security environment and control security of data using a first security key, and a secure memory configured to be operatively connected to the secure processor and store a second security key corresponding to the first security key. Various other embodiments are possible.

Claims (93)

1. An electronic device comprising:

a secure integrated circuit (IC) configured as a system-on-chip (SoC), the secure IC configured to provide a general environment and a security environment,

wherein the secure IC comprises:

a main processor configured to operate in the general environment;

a secure processor configured to operate in the security environment and control security of data using a first security key; and

a secure memory operatively connected to the secure processor and configured to store a second security key corresponding to the first security key,

wherein the secure processor comprises:

an encryption module configured to encrypt data by using the first security key;

a random-number generation module configured to generate a random number having a pre-defined number of bits;

a one-time programmable (OTP) memory;

a secure memory controller configured to control the secure memory; and

a processing module operatively connected to the encryption module, the random-number generation module, the OTP memory, and the secure memory controller,

wherein the processing module is configured to:

determine whether the first security key is recorded in the OTP memory, during initialization of the security environment, wherein the security environment is initialized at the time of a first booting of the electronic device due to initialization or update of the electronic device, and

when it is determined that the first security key is not recorded:

request the random-number generation module to generate a random key,

record the generated random key as the first security key in the OTP memory, and

transmit the generated random key to the secure memory via the secure memory controller so as to record the generated random key as the second security key in the secure memory,

wherein the processing module further comprises a security interface module which is based on software running on a secure operating system or a platform,

wherein the security interface module is configured to:

during invocation of the security environment, acquire the first security key from the OTP memory and transmit the acquired first security key to the encryption module, and

when a security application executed in the security environment requests storage of data:

transmit the data requested to be stored to the encryption module and request encryption of the data,

receive encrypted data encrypted using the first security key from the encryption module, and

transmit the received encrypted data to the secure memory via the secure memory controller, and

wherein the secure memory is further configured to:

decode the transmitted encrypted data by using the second security key, and

store the decoded data.

2. The electronic device of claim 1 , wherein the processing module is further configured to identify a bit value stored in a designated area of the OTP memory so as to determine whether the first security key is recorded.

3. The electronic device of claim 1 , wherein the processing module is further configured to identify a bit value stored in a designated area of the OTP memory so as to determine whether the second security key is recorded.

4. The electronic device of claim 1 ,

wherein the first security key is recorded in the OTP memory or the secure memory controller during manufacturing of the secure IC, and

wherein the second security key is recorded in the secure memory during manufacturing of the secure IC.

5. An electronic device comprising:

a secure integrated circuit (IC) which is of a system-on-chip (SoC) type, the secure IC comprising:

a main processor configured to operate in a general environment; and

a secure processor configured to operate in a security environment and control security of data using a first security key; and

a secure memory operatively connected to the secure processor of the secure IC and configured to store a second security key corresponding to the first security key,

wherein the secure processor comprises:

an encryption module configured to encrypt data by using the first security key;

a random-number generation module configured to generate a random number having a pre-defined number of bits;

a one-time programmable (OTP) memory;

a secure memory controller configured to control the secure memory; and

a processing module operatively connected to the encryption module, the random-number generation module, the OTP memory, and the secure memory controller,

wherein the processing module is configured to:

determine whether the first security key is recorded in the OTP memory, during initialization of the security environment, wherein the security environment is initialized at the time of a first booting of the electronic device due to initialization or update of the electronic device, and

when it is determined that the first security key is not recorded:

request the random-number generation module to generate a random key,

record the generated random key as the first security key in the OTP memory, and

transmit the generated random key to the secure memory via the secure memory controller so as to record the generated random key as the second security key in the secure memory,

wherein the processing module further comprises a security interface module which is based on software running on a secure operating system or a platform,

wherein the security interface module is configured to:

during invocation of the security environment, acquire the first security key from the OTP memory and transmit the acquired first security key to the encryption module, and

when a security application executed in the security environment requests storage of data:

transmit the data requested to be stored to the encryption module and request encryption of the data,

receive encrypted data encrypted using the first security key from the encryption module, and

transmit the received encrypted data to the secure memory via the secure memory controller, and

wherein the secure memory is further configured to:

decode the transmitted encrypted data by using the second security key, and

store the decoded data.

6. The electronic device of claim 5 , wherein the processing module is further configured to identify a bit value stored in a designated area of the OTP memory so as to determine whether the first security key is recorded.

7. The electronic device of claim 5 ,

wherein the first security key is recorded in the OTP memory or the secure memory controller during manufacturing of the secure IC, and

wherein the processing module is configured to, during initialization of the security environment:

load the first security key recorded in the OTP memory or the secure memory controller, and

cause the secure memory controller to record the second security key in the secure memory based on the loaded first security key.

8. An electronic device comprising:

a secure integrated circuit (IC) configured as a system-on-chip (SoC) and configured to provide a general environment and a security environment,

wherein the secure IC comprises:

a main processor configured to operate in the general environment;

a secure processor configured to operate in the security environment and control security of data using a security key; and

a non-secure memory operatively connected to the secure processor, wherein the secure processor comprises:

a memory controller configured to control the non-secure memory;

an encryption module configured to encrypt data by using the security key;

a random-number generation module configured to generate a random number having a pre-defined number of bits;

a one-time programmable (OTP) memory; and

a processing module configured to be operatively connected to the memory controller, the encryption module, the random-number generation module and the OTP memory,

wherein the processing module is configured to:

determine whether the security key is recorded in the OTP memory, during initialization of the security environment, wherein the security environment is initialized at the time of a first booting of the electronic device due to initialization or update of the electronic device, and

when it is determined that the security key is not recorded:

request the random-number generation module to generate a random key, and

record the generated random key as the security key in the OTP memory,

wherein the processing module further comprises a security interface module which is based on software running on a secure operating system or a platform, and

wherein the security interface module is configured to:

during invocation of the security environment, acquire the security key from the OTP memory and transmit the acquired security key to the encryption module, and

when a security application executed in the security environment requests storage of data:

transmit the data requested to be stored to the encryption module and request encryption of the data,

receive encrypted data encrypted using the security key from the encryption module, and

transmit the received encrypted data to the non-secure memory via the memory controller so as to store the encrypted data in the non-secure memory.

9. The electronic device of claim 8 , wherein the encrypted data is stored in a protected area of the non-secure memory.

10. The electronic device of claim 9 , wherein the protected area of the non-secure memory area is protected based on a Replay-Protected Memory Block (RPMB) scheme.

11. The electronic device of claim 8 ,

wherein the security key is recorded in the OTP memory during manufacturing of the secure IC.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2020
From: KIM, BUMHAN; KONG, SUNJUNE; CHO, SEONGJIN
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 052085/0304 →
Priority Claims (1)
KR 10-2019-0028203 · Mar 12, 2019 · national
Continuity (1)
Related Publication 20200293667A1 · Sep 17, 2020
Cited By (1)
US 12,659,190