EP1544704A1

Monolithic semiconductor integrated circuit and method for selective memory encryption and decryption

Abstract

A monolithic semiconductor integrated circuit is provided for selectively encrypting or decrypting data transmitted between one of a plurality of devices on the circuit and an external memory. Two series of data pathways connect the devices and the external memory. The first series of data pathways passes through a cryptographic circuit causing data to be encrypted or decrypted, and the other series of data pathways provides an unhindered route. When a data access request is made by a device, the data is selectively routed along one of the two series of data pathways according to the identification of the device making the data access request. In one example, if data is transmitted from a device to the external memory, the data is selectively encrypted before being stored in the external memory if the device transmitting the data is identified as secure. Then, when that data is retrieved from the external memory by a second device, the data is selectively decrypted only if the second device is identified as secure.

EP1544704A1, drawing sheet 1
Sheet 1 of 3

Term

Term ended

Projected expiry passed 19 December 2023, 2.8 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

28 claims: 6 independent, 22 dependent

  1. 1
    A monolithic semiconductor integrated circuit for selectively encrypting or decrypting data transmitted between one of a plurality of devices on the circuit and an external memory, the devices each having a unique identifier comprising:- a cryptographic circuit arranged to encrypt or decrypt data;- a plurality of selectable data routes formed from a plurality of data pathways, along which data may flow between the devices and the external memory, wherein at least one data route passes through the cryptographic circuit and at least one data route does not pass through the cryptographic circuit;and - a control arranged to receive the identification of a selected one of the devices transferring data, and to select one of the data routes that passes through the cryptographic circuit, or one of the data routes that does not pass through the cryptographic circuit, according to the identification of the selected device.
  2. 16
    A method for selectively encrypting or decrypting data transmitted between one of a plurality of devices, the devices each having a unique identifier, and an external memory, the data being transmitted along one of a plurality of selectable data routes formed from a plurality of data pathways, wherein at least one data route passes through a cryptographic circuit and at least one data route does not pass through the cryptographic circuit, comprising the steps of:- receiving the identification of a selected one of the devices;- selecting a data route that either passes through the cryptographic circuit, or one of the data routes that does not pass through the cryptographic circuit, according to the identification of the selected device.
  3. 21
    The method according to any of claims 16 to 20 wherein the plurality of devices includes at least one of, a crypto core, direct memory access unit, central processing unit, moving picture experts group decoder, read only memory, programmable transport interface, universal serial bus interface, or broadcast receiver.
  4. 22
    The method according to any of claims 16 to 21 wherein the data includes video data, audio data, encryption keys, or data broadcast over air.
  5. 23
    The method according to any of claims 16 to 22 further comprising the steps of:- transmitting data from a first device to the external memory;- selectively encrypting the data only if the first device is secure;- transmitting the data from the external memory to a second device;and - selectively decrypting the data only if the second device is secure.
  6. 24
    The method according to any of claims 16 to 23 wherein the external memory is separated into a plurality of mutually exclusive regions, the method further comprising the steps of:- determining which region of the external memory is being accessed;- selectively blocking the data accesses to or from the external memory according to the identification of the device requesting the data access, and according to which region of the external memory is being accessed.