IP Library › Granted Patent US 12,602,333
Granted Patent B2
US 12,602,333 · App. 18/342,969 · Granted Apr 14, 2026

Secure element and electronic device including the same

Inventors: Sunghyun Kim (Suwon-si, KR); Keunyoung Park (Suwon-si, KR)
Assignee: Samsung Electronics Co., Ltd.
G06F12/1408G06F13/28G06F21/72H04L9/3242G06F21/71G06F21/79G06F2212/1052H04L63/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,602,333
App. No.
18/342,969
Granted
Apr 14, 2026
Kind
B2
Abstract

A secure element (SE) coupled to a system-on-chip (SoC) includes an internal memory, virtual secure direct memory access (DMA) circuitry configured to perform a secure operation using an external memory connected to the SoC in association with the internal memory, and SE interface circuitry configured to output secure data and a write request generated by the virtual secure DMA circuitry to the SoC, the secure data being stored in the external memory.

Claims (81)

1 . A secure element (SE) coupled to a system-on-chip (SoC), the SE comprising:

an internal memory;

virtual secure direct memory access (DMA) circuitry configured to

perform a secure operation using an external memory connected to the SoC in association with the internal memory,

perform a hash operation using a hash key on a first packer including first data and an anti-replay counter (ARC) to generate a first tag and

perform an encryption operation using an encryption key on a second packet including the first tag and the first data to generate first secure data; and

SE interface circuitry configured to output the first secure data and a write request generated by the virtual secure DMA circuitry to the SoC,

the first secure data being stored in the external memory.

2 . The SE of claim 1 , wherein the internal memory includes a non-volatile memory storing an ARC table including the ARC.

3 . The SE of claim 2 , wherein

the SE interface circuitry is configured to output second secure data received from the SoC to the virtual secure DMA circuitry in response to a read request for the first secure data, and

the virtual secure DMA circuitry is configured to perform a decryption operation using a decryption key on the second secure data to generate a third packet including second data and a second tag, perform a second hash operation using the hash key on a fourth packet including the second data and the ARC read from the non-volatile memory to generate a third tag, and perform integrity verification on the second data by comparing the second tag with the third tag.

4 . The SE of claim 1 , wherein

the internal memory includes:

a cache memory configured to store a plurality of secure applications; and

a non-volatile memory configured to store hash keys, encryption keys, and ARC tables corresponding to each of the plurality of secure applications.

5 . The SE of claim 4 , wherein

the SE interface circuitry includes a plurality of SE interfaces, and

the virtual secure DMA circuitry is configured to

select one of the plurality of SE interfaces for communication with the SoC, and

perform the secure operation based on an executed secure application, among the plurality of secure applications.

6 . The SE of claim 5 , wherein

the plurality of SE interfaces are configured to support different communication rates, and

the virtual secure DMA circuitry is configured to select any one of the plurality of SE interfaces based on a data update frequency of the executed secure application.

7 . The SE of claim 4 , wherein

the virtual secure DMA circuitry includes a plurality of submodules configured to perform the secure operation based on each of executed secure applications among the plurality of secure applications, and

the SE interface circuitry includes a plurality of SE interfaces that are respectively dedicated to the plurality of submodules and configured to perform communication with the SoC.

8 . The SE of claim 4 , wherein

the SE interface circuitry includes a plurality of SE interfaces configured to perform communication with the SoC, and

the virtual secure DMA circuitry includes:

a plurality of submodules configured to perform the secure operation based on each of executed secure applications among the plurality of secure applications; and

a switching module configured to control a connection between the plurality of submodules and the plurality of SE interfaces.

9 . The SE of claim 1 , further comprising:

a memory management unit (MMU) configured to determine whether an available page exists in the internal memory using a translation lookaside buffer (TLB),

wherein the virtual secure DMA circuitry is configured to perform the secure operation based on a result of the determination.

10 . The SE of claim 1 , further comprising:

a pin configured to receive a signal indicating whether the external memory is available from the SoC,

wherein the virtual secure DMA circuitry is configured to perform the secure operation based on the signal.

11 . An electronic device comprising:

an external memory;

a system-on-chip (SoC) coupled to the external memory; and

a first secure element (SE) coupled to the SoC,

the first SE including:

an internal memory;

a memory management unit configured to determine whether an available page exists in the internal memory using a translation lookaside buffer;

first SE interface circuitry configured to transmit first secure data to the SoC to write the first secure data to the external memory based an a result of the determination and receive the first secure data read from the external memory, from the SoC; and

first virtual secure DMA circuitry configured to generate the first secure data based on a set anti-replay counter (ARC) and a hash key and an encryption key read from a non-volatile memory of the first SE and perform a verification operation on the first secure data.

12 . The electronic device of claim 11 , wherein

the SoC includes:

first interface circuitry configured to transmit and receive the first secure data to and from the first SE interface circuitry;

a first input/output (I/O) interface circuitry configured to transmit and receive the first secure data to and from the external memory; and

first DMA circuitry configured to control writing of the first secure data to and reading of the first secure data from the external memory.

13 . The electronic device of claim 11 , further comprising:

a second SE coupled to the SoC,

wherein the second SE includes:

second SE interface circuitry configured to transmit second secure data to the SoC to write the second secure data to the external memory and receive the second secure data read from the external memory, from the SoC; and

second virtual secure DMA circuitry configured to generate the second secure data and perform a second verification operation on the second secure data.

14 . The electronic device of claim 13 , wherein the external memory includes:

a first memory region for the first SE; and

a second memory region for the second SE and physically or logically separated from the first memory region.

15 . The electronic device of claim 11 , wherein the first SE further includes the non-volatile memory configured to store the hash key, the encryption key, and an ARC table,

and

the set ARC is included in the ARC table.

16 . The electronic device of claim 11 , wherein the first SE includes:

a cache memory configured to store a plurality of secure applications; and

a non-volatile memory configured to store hash keys, encrypt keys, and ARC tables corresponding to each of the plurality of secure applications.

17 . The electronic device of claim 16 , wherein the first virtual secure DMA circuitry is configured to perform a generation operation or the verification operation on the first secure data based on an executed secure application among the plurality of secure applications.

18 . The electronic device of claim 17 , wherein

the first SE interface circuitry includes a plurality of SE interfaces, and

the first virtual secure DMA circuitry is configured to select any one of the plurality of SE interfaces based on the executed secure application for communication with the SoC.

19 . An electronic device comprising:

a first external memory;

a second external memory;

a first integrated circuit (IC) coupled to the first external memory; and

a second IC coupled to the second external memory,

the first IC including:

first interface circuitry configured to transmit first secure data to the second IC to write the first secure data to the second external memory and receive the first secure data read from the second external memory, from the second IC; and

first virtual secure direct memory access (DMA) circuitry configured to

perform a hash operation using a hash key on a first packet including first data and a set anti-replay counter (ARC) to generate a first tag,

perform an encryption operation using an encryption key on a second packet including the first tax and the first data to generate the first secure data in a generation operation, and

perform a verification operation on the first secure data.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 18, 2023
From: KIM, SUNGHYUN; PARK, KEUNYOUNG
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 064298/0277 →
Priority Claims (2)
KR 10-2022-0080001 · Jun 29, 2022 · national
KR 10-2022-0105777 · Aug 23, 2022 · national
Continuity (1)
Related Publication 20240004803A1 · Jan 4, 2024
References Cited (16)
US 8799678B2 · Buer · 2014 [cited by applicant]
US 8812804B2 · Goss et al. · 2014 [cited by applicant]
US 9063891B2 · Kegel · 2015 [cited by examiner]
US 10637647B2 · Temple · 2020 [cited by examiner]
US 10719606B2 · Sanchez Diaz et al. · 2020 [cited by applicant]
US 10853519B2 · Pan · 2020 [cited by applicant]
US 10949546B2 · Chung et al. · 2021 [cited by applicant]
US 20060095793A1 · Hall · 2006 [cited by examiner]
US 20160026799A1 · Hershman · 2016 [cited by examiner]
US 20160299854A1 · Deivasigamani · 2016 [cited by examiner]
US 20190042765A1 · Chung · 2019 [cited by examiner]
US 20190130120A1 · Lal · 2019 [cited by examiner]
US 20200127836A1 · Pappachan · 2020 [cited by examiner]
US 20200358620A1 · Kim et al. · 2020 [cited by applicant]
US 20210149824A1 · Satpathy · 2021 [cited by examiner]
EESR dated Oct. 6, 2023 for corresponding EP Patent Application No. 23182451.7. [cited by applicant]