IP Library › Granted Patent US 12,549,359
Granted Patent B2
US 12,549,359 · App. 18/782,322 · Granted Feb 10, 2026

Micro-controller, secure system, and protection method

Inventor: Zong-Min Lin (Kaohsiung, TW)
Assignee: NUVOTON TECHNOLOGY CORPORATION
H04L9/0894G06F21/107G06F21/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,549,359
App. No.
18/782,322
Granted
Feb 10, 2026
Kind
B2
Abstract

A micro-controller including a secure world, a non-secure world, and a processing circuit is provided. The secure world includes a key management device, a decryption circuit, and a first memory. The key management device stores a secret key. The decryption circuit utilizes the secret key to decrypt an encrypted model to generate a decrypted model. The first memory stores the decrypted model. The non-secure world includes a second memory and a third memory. The second memory stores the encrypted model. The third memory stores an inference result. The processing circuit provides input data to the decrypted model. The decrypted model generates the inference result according to the input data.

Claims (75)

1 . A micro-controller comprising:

a secure world comprising:

a key management device storing a secret key;

a decryption circuit utilizing the secret key to decrypt an encrypted model to generate a decrypted model; and

a first memory storing the decrypted model;

a non-secure world comprising:

a second memory storing the encrypted model; and

a third memory storing an inference result; and

a processing circuit providing input data to the decrypted model,

wherein the decrypted model generates the inference result according to the input data,

wherein in a non-secure mode, the processing circuit reads the encrypted model stored in the second memory and calls a software function,

wherein the processing circuit provides addresses of the encrypted model, the input data and the inference result to the software function, and

wherein in a secure mode, the processing circuit executes the software function to:

direct the decryption circuit to read the secret key;

direct the decryption circuit to utilize the secret key to decrypt the encrypted model to generate the decrypted model; and

store the decrypted model in the first memory.

2 . The micro-controller as claimed in claim 1 , wherein the software function is stored in the secure world.

3 . The micro-controller as claimed in claim 1 , wherein the processing circuit enters the secure mode and executes the software function.

4 . The micro-controller as claimed in claim 1 , wherein in the secure mode, the processing circuit further executes the software function to:

execute the decrypted model to generate the inference result;

store the inference result in the third memory; and

enter the non-secure mode.

5 . The micro-controller as claimed in claim 1 , wherein the non-secure world further comprises:

a transmission interface configured to receive the encrypted model.

6 . The micro-controller as claimed in claim 5 , wherein the transmission interface is an internet interface.

7 . The micro-controller as claimed in claim 1 , wherein the second memory is a non-volatile memory, and each of the first and third memories is a volatile memory.

8 . The micro-controller as claimed in claim 1 , wherein the decrypted model is a neural network model.

9 . A secure system, comprising:

a micro-controller comprising:

a secure world comprising:

a key management device storing a secret key;

a decryption circuit utilizing the secret key to decrypt an encrypted model to generate a decrypted model; and

a first memory storing the decrypted model;

a non-secure world comprising:

a second memory storing the encrypted model; and

a third memory storing an inference result;

a processing circuit providing input data to the decrypted model, wherein the decrypted model generates the inference result according to the input data, and the processing circuit stores the inference result in the third memory; and

an offline tool comprising:

an encryption circuit utilizing the secret key to encrypt a network model to generate the encrypted model and storing the encrypted model in the second memory,

wherein in a non-secure mode, the processing circuit reads the encrypted model stored in the second memory and calls a software function,

wherein the processing circuit provides addresses of the encrypted model, the input data and the inference result to the software function, and

wherein in a secure mode, the processing circuit executes the software function to:

direct the decryption circuit to read the secret key;

direct the decryption circuit to utilize the secret key to decrypt the encrypted model to generate the decrypted model; and

store the decrypted model in the first memory.

10 . The secure system as claimed in claim 9 , wherein the encryption circuit utilizes the secret key to execute a symmetric encryption operation for the network model, and the decryption circuit utilizes the secret key to execute a symmetric decryption operation for the encrypted model.

11 . The secure system as claimed in claim 9 , wherein the offline tool further comprises:

a provision circuit provisioning the secret key to the key management device.

12 . The secure system as claimed in claim 9 , wherein the offline tool is independent of the micro-controller.

13 . A protection method applied in a processing circuit and comprising:

in a non-secure mode:

reading an encrypted model in a non-secure world;

calling a software function in a secure world; and

entering a secure mode; and

in the secure mode:

executing the software function to:

read a secret key in the secure world;

utilize the secret key to decrypt the encrypted model to generate a decrypted model; and

execute the decrypted model to generate an inference result,

wherein in the non-secure mode, the encrypted model is read and a software function is called,

wherein the method further comprising in the non-secure mode, providing addresses of the encrypted model, the input data and the inference result to the software function, and

wherein in the secure mode, executing the software function to:

direct the decryption circuit to read the secret key;

direct the decryption circuit to utilize the secret key to decrypt the encrypted model to generate the decrypted model; and

store the decrypted model in the first memory.

14 . The protection method as claimed in claim 13 , wherein the decrypted model is stored in the secure world.

15 . The protection method as claimed in claim 13 , further comprising:

in the secure mode:

storing the inference result in the non-secure world; and

in the non-secure mode:

reading the inference result in the non-secure world.

16 . The protection method as claimed in claim 13 , further comprising:

encrypting a network model to generate the encrypted model;

utilizing an internet to transmit the encrypted model to the non-secure world; and

provisioning the secret key to the secure world.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2025
From: LIN, ZONG-MIN
To: NUVOTON TECHNOLOGY CORPORATION
Reel/Frame 072437/0355 →
Priority Claims (1)
TW 112131442 · Aug 22, 2023 · national
Continuity (1)
Related Publication 20250070969A1 · Feb 27, 2025
References Cited (9)
US 12001577B1 · Xiong · 2024 [cited by examiner]
US 20190296910A1 · Cheung · 2019 [cited by examiner]
US 20200019697A1 · Shen · 2020 [cited by examiner]
US 20230155819A1 · Shin · 2023 [cited by examiner]
CN 103427984B · 2018 [cited by applicant]
CN 114266060A · 2022 [cited by applicant]
TW 202028991A · 2020 [cited by applicant]
TW 202145041A · 2021 [cited by applicant]
WO WO2016040536A1 · 2020 [cited by applicant]