Method and system for reliable and secure memory erasure

Through the combination of the switching matrix and the decoupling capacitor, the polarity of the fast flip capacitor provides a negative power supply to the safe RAM block, solving the problem of long and unreliable erasing time in the prior art, and achieving fast and reliable erasing of the safe RAM block.

CN114503200BActive Publication Date: 2025-08-12MICROCHIP TECHNOLOGY INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080070648.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2020-07-02
Filing Date
2020-07-06
Publication Date
2025-08-12
Estimated Expiration
2040-07-06

AI Technical Summary

Technical Problem

In the prior art, methods of erasing secure random access memory (RAM) blocks are time-consuming and unreliable and susceptible to tampering, and conventional methods may lead to sensitive data leakage.

Method used

Using a combination of a switching matrix and a decoupling capacitor, a negative power supply is provided to a secure RAM block for fast and reliable erasing by quickly flipping the capacitor polarity through the control signal.

Benefits of technology

The fast erase of secure RAM blocks is realized, and the erase time is more than 1000 times faster than conventional methods, ensuring data security and reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114503200B_ABST
    Figure CN114503200B_ABST
Patent Text Reader

Abstract

A memory device has a switch matrix having a power supply input, a control input, and a power supply output; and a random access memory having a power connection coupled to the power supply output of the switch matrix. The switch matrix has a capacitor that can be charged by the power supply, and upon receiving a control signal via the control input, the switch matrix is configured to decouple the capacitor from the power supply and the random access memory and couple the capacitor to the random access memory via the power supply output with reverse polarity, thereby providing a negative power supply to the power supply output.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Priority Declaration

[0002] This patent application claims priority to U.S. Provisional Application No. 62 / 957,541, filed on January 6, 2020, which is incorporated herein by reference as if fully and entirely set forth herein. Technical Field

[0003] The present disclosure relates to memory, particularly memory embedded in, for example, a microcontroller. Background Art

[0004] Microcontrollers or embedded systems may include dedicated random access memory (RAM) blocks for storing intermediate and sensitive data. RAM memory is often divided into several sections based on its use case; one such use case is storing secure information. In contrast to flash memory, such dedicated RAM blocks can provide sensitive data to the central processing unit more quickly. Such dedicated RAM blocks are typically not accessible to users. Figure 1 A typical embedded system 100 is shown that includes a central processing unit (CPU) or hardware security module (HSM) 120 coupled to a system RAM block 130. A RAM block 140 (hereinafter referred to as a trusted RAM block 140) for storing sensitive security data (such as sensitive security key information) is separate from the system RAM block 130. The CPU or HSM 120 or trusted RAM block 140 may include logic components that prevent general access to the trusted RAM block 140. In addition, a tamper detector or sensor unit 110 may be included that indicates any attempt to tamper with the embedded system 100 to the CPU or HSM 120 or to a device external to the embedded system 100. In response to such an attempt, the embedded system 100 is configured to erase the trusted RAM block 140.

[0005] Conventional systems erase trusted RAM blocks 140 by writing "1" and "0" to the entire trusted RAM block 140 to ensure that all bits are overwritten. However, this process takes a long time, which is undesirable. Conventional methods for erasing trusted RAM blocks 140 (e.g., 1KB to 8KB RAM blocks) take several milliseconds and are unreliable. Conventional methods can be altered in the middle through simple operations such as power and clock tampering, which may make one or more keys vulnerable.

[0006] Another method of erasing the trusted RAM block 140 can include shorting the power supply for the trusted RAM block 140 to ground. Unfortunately, near the threshold voltage Vth, the gates of the transistors erasing the trusted RAM block 140 discharge at a slower rate, which results in a long discharge of the power input. The erase attempt can be interrupted before completion, and the differential charge on the bit cells of the trusted RAM block 140 can be read while the supply voltage is still between Vdd and Vth, thereby potentially recovering the information stored in the trusted RAM block 140. Summary of the Invention

[0007] Therefore, there is a need for an improved method and system for reliably erasing secure memory, particularly secure random access memory.

[0008] According to one embodiment, a memory device may include: a switch matrix including a power input, a control input and a power output; a random access memory having a power connection portion coupled to the power output of the switch matrix, wherein the switch matrix includes a capacitor that can be charged by a power supply coupled to the power input, and wherein when a control signal is received through the control input, the switch matrix is designed to decouple the capacitor from the power input and the power output, and couple the capacitor to the random access memory through the power output with reverse polarity.

[0009] According to another embodiment, the random access memory may be a secure random access memory within an embedded system. According to another embodiment, the matrix may include a first set of switches coupling the capacitor to the power supply input and a second set of switches for coupling the capacitor to the power supply output. According to another embodiment, the second set of switches may include a first pair of switches and a second pair of switches, the first pair of switches being configured to couple the capacitor to the power supply output with a first polarity, and the second pair of switches being configured to couple the capacitor to the power supply output with a second polarity, wherein the second polarity is an opposite polarity relative to the first polarity. According to another embodiment, the switch matrix may be controlled to keep the first pair of switches in the first and second sets of switches closed during normal operation, while keeping the second pair of switches in the second set of switches open. According to another embodiment, upon receiving the control signal, the switch matrix may be configured to open the first pair of switches in the second set of switches and the first set of switches, and then close the second pair of switches in the second set of switches. According to another embodiment, the switches in the second set of switches can be controlled by a single switch control signal, wherein the first pair of switches are designed to operate faster than the second pair of switches. According to another embodiment, the first pair of switches can be controlled by a first switch control signal and the second pair of switches are controlled by a second switch control signal, wherein to reverse the polarity of the capacitor, the first switch control signal is configured to be asserted before the second switch control signal. According to another embodiment, the switches in the first set of switches can be controlled to open after the first pair of switches in the second set of switches. According to another embodiment, the capacitance of the capacitor can be approximately 10 times the total bit cell capacitance of the random access memory. According to another embodiment, the size of the switch for coupling the capacitor with reverse polarity can be set to 3τ (tau).

[0010] According to another embodiment, a microcontroller may comprise a memory device as defined above, wherein the microcontroller forms an embedded system. According to another embodiment, a hardware security module may be coupled to such a memory device.

[0011] According to another embodiment, a method for operating a memory device may include: providing a power supply voltage to a random access memory via a switch matrix, wherein the switch matrix includes a power supply input, a power supply output, and a capacitor charged by the power supply voltage; receiving a control signal instructing to erase the memory, and upon receiving the control signal for erasing the memory, decoupling the capacitor from the power supply and the random access memory through the switch matrix, and then coupling the capacitor to the power supply output with reverse polarity.

[0012] According to another embodiment of such a method, the random access memory may be a secure random access memory within an embedded system. According to another embodiment of such a method, the switch matrix may include a first set of switches for coupling the capacitor to the power supply input and a second set of switches for coupling the capacitor to the power supply output, wherein the second set of switches includes a first pair of switches and a second pair of switches, the first pair of switches being configured to couple the capacitor to the power supply output with a first polarity, and the second pair of switches being configured to couple the capacitor to the power supply output with a second polarity, wherein the second polarity is an opposite polarity relative to the first polarity. According to another embodiment of such a method, the method may further include, when the control signal is not received, controlling the first pair of switches in the first and second sets of switches to close while keeping the second pair of switches in the second set of switches open. According to another embodiment of such a method, when the control signal is received, the method may provide for controlling the first pair of switches in the second set of switches to open and then closing the second pair of switches in the second set of switches. According to another embodiment of such a method, the switches in the second set of switches can be controlled by a single switch control signal, wherein the first pair of switches are designed to operate faster than the second pair of switches. According to another embodiment of such a method, the first pair of switches can be controlled by a first switch control signal and the second pair of switches are controlled by a second switch control signal, wherein to reverse the polarity of the capacitor, the first switch control signal is asserted before the second switch control signal. According to another embodiment of such a method, the switches in the first set of switches can be controlled to open after the first pair of switches in the second set of switches are controlled to open. According to another embodiment of such a method, the capacitance of the capacitor can be approximately 10 times the total bit cell capacitance of the random access memory. According to another embodiment of such a method, the size of the switch for coupling the capacitor with reverse polarity can be set to 3τ (tau). BRIEF DESCRIPTION OF THE DRAWINGS

[0013] Figure 1 A conventional embedded system with a secure RAM block is shown.

[0014] Figure 2 An embodiment of an improved secure RAM block with fast erase functionality is shown.

[0015] Figure 3 An embedded system with a secure RAM block is shown according to one embodiment.

[0016] Figure 4 A first embodiment of a switch matrix is shown.

[0017] Figure 5A timing diagram of switch control signals used in the first embodiment is shown.

[0018] Figure 6 A second embodiment of a switch matrix is shown.

[0019] Figure 7 A timing diagram of switch control signals used in the second embodiment is shown. DETAILED DESCRIPTION

[0020] According to one embodiment, the reliable erase function of such a trusted RAM block can apply a negative supply voltage to its power supply. However, since these systems are typically CMOS devices, generating a negative power supply in a CMOS process can be difficult and expensive.

[0021] According to various embodiments, a memory device includes a switch matrix having a power supply input, a control input, and a power supply output; and a random access memory block having a power connection coupled to the power supply output of the switch matrix. The switch matrix includes a capacitor capable of being charged by the power supply, and upon receiving a control signal via the control input, the switch matrix is configured to decouple the capacitor from the power supply and the random access memory block and couple the capacitor with reverse polarity through the power supply output to the random access memory block, thereby providing a negative power supply to the power supply output.

[0022] According to various embodiments, a set of series switches is used to provide power to the trusted RAM block. These switches allow the system to isolate the trusted RAM block power supply. The trusted RAM block comes with decoupling capacitors that provide sufficient decoupling capacitance. Once the decoupling capacitors are charged and isolated, another set of switches can be used to flip the decoupling capacitors connected to the trusted RAM block's power supply. In this way, the decoupling capacitors act like batteries for the trusted RAM block. Flipping the decoupling capacitors is like applying negative battery voltage to the trusted RAM block's power input. As a result, the trusted RAM block can be quickly erased.

[0023] The advantage of the solution enabled herein is that a trusted RAM block can be erased with a constant and decoupling value that is three times the RC time constant of the switch. The trusted RAM block erase time enabled by the implementation herein is more reliable than writing "1" and "0" and is over 1000 times faster. The larger the RAM, the faster the erase speed, compared to the conventional solution of writing "0" and "1" to the entire RAM.

[0024] Figure 2An embodiment of an improved secure RAM or trusted RAM block 140 is shown. Power is provided to the trusted RAM block 140, for example, via a dedicated voltage regulator (not shown), which provides voltages on power supply lines Vdd and Vss. This power supply can be a common power supply used for various other parts of the embedded system, or it can be a dedicated power supply that provides power only to the trusted RAM block 140. A switch matrix 210 is coupled between the power supply lines Vdd and Vss and the trusted RAM block 140, such that the power supply lines Vdd and Vss are coupled to the power inputs of the switch matrix 210. The switch matrix 210 is configured to provide a negative voltage to the trusted RAM block 140 under the control of the secure element, or the CPU or HSM 120. In normal operation, the switch matrix 210 connects the Vdd supply line coupled to the power input of the switch matrix 210 to the Vdd_tram line of the power output of the switch matrix 210 coupled to the corresponding power connection of the trusted RAM block 140, and connects the Vss supply line coupled to the power input of the switch matrix 210 to the Vss_tram line of the power output of the switch matrix 210 coupled to the corresponding power connection of the trusted RAM block 140, so that a positive voltage is provided to the trusted RAM block 140 at the power connection of the trusted RAM block 140 through the lines Vdd_tram and Vss_tram. When the switch matrix 210 receives an asserted control signal through the line Ctrl indicating that the trusted RAM block 140 is to be erased, the switch matrix 210 provides a negative voltage supply through the lines Vdd_tram and Vss_tram coupled to the power connection of the trusted RAM block 140. To this end, the switch matrix 210 may include a capacitor that is charged by a power supply provided between the power supply lines Vdd and Vss, and the capacitor may be switchably disconnected from the power supply lines Vdd and Vss. The switch matrix 210 further includes a switch that allows the polarity of the capacitor to be flipped relative to the lines Vdd_tram and Vss_tram (i.e., relative to the power supply output of the switch matrix 210). Thus, a reverse supply voltage or a negative supply voltage is provided to the lines Vdd_tram and Vss_tram, thereby enabling fast erasure of the trusted RAM block 140.

[0025] Figure 3 Schematic diagram showing how the switch matrix 210 is embedded in the embedded system 300. Figure 1 Similar components in Figure 3 Similar or identical reference numerals are used. Figure 3 Similar to Figure 1FIG3 illustrates an embedded system in which a voltage regulator 310, which may be present on the embedded system 300, provides power to the trusted RAM block 140 via the switch matrix 210. The voltage regulator 310 may also provide power to other components of the embedded system 300. However, the supply voltage for the trusted RAM block 140 may also be provided externally, as indicated by the dashed line, and provided by an external voltage regulator 320. The switch matrix 210 is disposed between the voltage regulator 310 and the trusted RAM block 140 and receives control signals from the CPU or HSM 120. In the event that the supply voltage for the trusted RAM block 140 is provided by the external voltage regulator 320, the switch matrix 210 is disposed between the external voltage regulator 320 and the trusted RAM block 140. The switch matrix 210 has a power input coupled to the output of the voltage regulator 310 and also has a power output coupled to the power connection of the trusted RAM block 140. The switch matrix 210 also has a control input that receives control signals from the CPU or HSM 120.

[0026] During normal operation, the switch matrix 210 is controlled by the deasserted state of a control signal from the CPU or HSM 120 to provide the output of the voltage regulator 310 or 320 to the power line connection of the trusted RAM block 140. When tampering is detected by the tamper detector 110, in response to the signal from the tamper detector 110, the CPU or HSM 120 asserts a control signal to the switch matrix 210, causing the switch matrix 210 to provide a reverse power supply or negative power supply to the power connection of the trusted RAM block 140, thereby erasing the entire contents of the trusted RAM block 140. Tampering can be detected by the tamper detector 110, for example, by generating an internal tamper event signal sent to the CPU or HSM 120 upon detection of a power failure, a clock failure, a temperature out-of-range event, a voltage out-of-range event, or by detecting the decapsulation of a module or integrated circuit. Similarly, other possible tampering events can be detected by the tamper detector 110. Once such a tampering event has been detected by the tamper detector 110, the contents of the trusted RAM block 140 are preferably erased as quickly as possible. Fast erasure of the contents of the trusted RAM block 140 is achieved by providing an inverted or negative power supply output of the switch matrix 210 coupled to the power supply connections of the trusted RAM block 140 .

[0027] Figure 4A first embodiment of the switch matrix 210 is shown. A first set of switches, including switches 410a and 410b, can couple a supply voltage received via power supply lines Vdd and Vss to respective leads of a capacitor 440. The second set of switches, including first and second switch pairs 420a, 420b, 430a, 430b, respectively, can be controlled to provide the voltage across the leads of capacitor 440 to output lines Vdd_tram and Vss_tram of the power supply output of switch matrix 210 in one of the following polarities: a first polarity that matches the polarity of power supply lines Vdd and Vss when first switch pair 420a, 420b is closed and second switch pair 430a, 430b is open; and a second polarity opposite to the first polarity, in which, when first switch pair 420a, 420b is open and second switch pair 430a, 430b is closed, output lines Vdd_tram and Vss_tram of the power supply output of switch matrix 210 are connected to the power supply connection of trusted RAM block 140. Control logic 450 can generate the necessary control signals for switch pairs 410, 420, and 430.

[0028] exist Figure 4 In one embodiment, a first set of switches, including switches 410a and 410b, are connected in series with power input lines Vdd and Vss, respectively, and are used to disconnect capacitor 440 from power input lines Vdd and Vss. A second set of switches includes a first pair of switches 420a and 420b, respectively, and a second pair of switches 430a and 430b. The first pair of switches are arranged in series to connect capacitor 440 to power input lines Vdd_tram and Vss_tram, respectively, with a first polarity, and the second pair of switches are arranged as a series crossbar switch to flip the polarity of capacitor 440 relative to power input lines Vdd_tram and Vss_tram. Therefore, when the first pair of switches 420a and 420b are closed and the second pair of switches 430a and 430b are open, a first terminal of capacitor 440 is coupled to line Vdd_tram, and a second terminal of capacitor 440 is coupled to line Vss_tram. When the first pair of switches 420a, 420b are open and the second pair of switches 430a, 430b are closed, the first terminal of the capacitor 440 is coupled to the line Vss_tram, and the second terminal of the capacitor 440 is coupled to the line Vdd_tram. Thus, the first set of switches 410a, 410b is used to couple the capacitor 440 to the power supply lines Vdd, Vss, and the second set of switches 420a, 420b and 430a, 430b are configured to alternately couple the capacitor 440 to the power supply outputs Vdd_tram, Vss_tram in a first polarity and a second polarity, wherein the second polarity is an opposite polarity relative to the first polarity.

[0029] To maintain the charge on the decoupling capacitor 440, the second set of switches 420a, 420b and 430a, 430b are flipped in a "break-before-make" manner. First, the power supply lines Vdd, Vss are disconnected via the first set of switches 410a, 410b. To reverse the polarity, the first pair of switches 420a, 420b is opened. Preferably, the first set of switches 410a, 410b is opened immediately before the first pair of switches 420a, 420b is disconnected. After decoupling the capacitor 440 from the power supply lines Vdd, Vss, the decoupling capacitor 440 is flipped, and the flipped capacitor 440 is then connected back to provide power to the trusted RAM block 140 at its power supply connections, i.e., the flipped capacitor 440 is then connected to the lines Vdd_tram, Vss_tram. This can be achieved by designing the first pair of switches 420a, 420b to be faster than the second pair of switches 430a, 430b or by providing a delay between the output of the control logic component 450 and the control input of the second pair of switches 430a, 430b. Thus, according to one embodiment, once the first set of switches 410a, 10b is opened, the first pair of switches 420a, 420b is controlled to be open, and the second pair of switches 430a, 430b is controlled to be closed. Because the first pair of switches 420a, 420b is specifically designed to operate faster than the second pair of switches 430a, 430b, the capacitor 440 is first separated from the outputs Vdd_tram and Vss_tram. Then, after a short delay, the second pair of switches 430a, 430b is closed, causing the capacitor 440 to flip relative to the outputs Vdd_tram and Vss_tram and providing the negative voltage stored on the capacitor 440 to the power supply connection of the trusted RAM block 140.

[0030] The control logic component 450 may receive a single control signal from the CPU or HSM 120 and may be designed to provide corresponding delays for the first switch control signal for the first set of switches 410a, 410b and the second switch control signal for the first pair of switches 420a, 430b and the second pair of switches 430a, 430b. Figure 4As shown, the first pair of switches 420a, 420b, shown with inverter signs, are designed to operate inversely relative to the second pair of switches 430a, 430b. In other words, when the second switch control signal from the control logic component 450 is in a state in which the first pair of switches 420a, 420b are controlled to be open, the second pair of switches 430a, 430b are controlled to be closed, and when the second switch control signal from the control logic component 450 is in a state in which the first pair of switches 420a, 420b are controlled to be closed, the second pair of switches 430a, 430b are controlled to be open. In addition, the first pair of switches 420a, 420b are designed to operate faster than the second pair of switches 430a, 430b when in the open state, so as to provide the necessary "break-before-make" function. Figure 5 Also shown are examples of possible first and second control signals for the switch 410 and the switches 420 / 430 , wherein the first pair of switches 420 a , 420 b and the second pair of switches 430 a , 430 b operate with the aforementioned delays. Figure 5 A corresponding timing diagram is shown, where a logic high for the first control signal controls the first set of switches 410a, 410b to be closed, and a logic low for the first control signal controls the first set of switches 410a, 410b to be open. A logic low for the second control signal controls the first pair of switches 420a, 420b to be closed, and a logic high for the second control signal controls the first pair of switches 420a, 420b to be open. The timing diagram shows a short delay between switching of the first set of switches 410a, 410b and the second set of switches 420a, 420b, 430a, 430b. The delay between the first pair of switches 420a, 420b and the second pair of switches 430a, 430b is inherent, as described above.

[0031] Alternatively, instead of the control logic component 450, the CPU may provide a separate first control signal for the first set of switches 410a, 410b and a separate second control signal for each of the first pair of switches 420a, 420b and the second pair of switches 430a, 430b, as described below with respect to Figure 6 and Figure 7 described.

[0032] Figure 6 Another embodiment of the switch matrix 210 is shown, which operates similarly to Figure 4. Here, the first pair of switches 420a, 420b and the second pair of switches 430a, 430b do not receive the same control signal from the control logic unit 550, but are controlled by separate switch control signals provided by the control logic unit 550 or directly by the CPU or HSM 120. In this embodiment, all switches can be designed to operate similarly. Since the first pair of switches 420a, 420b and the second pair of switches 430a, 430b are controlled separately, the control signals with the necessary delays are generated by the control logic unit 550 or by the CPU or HSM 120. Figure 6 In one embodiment, during normal operation, the first set of switches 410a, 410b and the first pair of switches 420a, 420b are controlled to be closed, and the second pair of switches 430a, 430b are controlled to be open. Once tampering has been detected, the first set of switches 410a, 410b and the first pair of switches 420a, 420b are opened to isolate the capacitor 440. The timing between opening the first set of switches 410a, 410b and the first pair of switches 420a, 420b is not critical, but preferably, the first pair of switches 420a, 420b is opened just before the first set of switches 410a, 410b is opened. Once the capacitor 440 is isolated from the power supply and from the power supply outputs of the lines Vdd_tram and Vss_tram, the second pair of switches 430a, 430b is closed to apply the negative supply voltage to the power supply connections of the trusted RAM block 140. Figure 7 Also shown are examples of possible first, second, and third control signals for the first set of switches 410a, 410b, the first pair of switches 420a, 420b, and the second pair of switches 430a, 430b. A logic high on the corresponding switch control signal controls the corresponding switches 410a, 410b, 420a, 420b, and 430a, 430b to be closed, and a logic low controls them to be opened. As shown here, the second control signal controlling the first pair of switches 420a, 420b transitions shortly before the control signal controlling the first set of switches 410a, 410b. However, the control signal for the first pair of switches 420a, 420b can also be designed to transition shortly after the first set of switches 410a, 410b transitions.

[0033] According to one embodiment, capacitor 440 can be designed to have a capacitance of approximately ten times the total bit cell capacitance of trusted memory block 140. However, other factors may apply. According to one embodiment, the size of at least the second switch group for reversing polarity can preferably be 3τ(tau) in Tclk. However, the size of all switches in the switch matrix can be 3τ(tau). By setting the capacitance of capacitor 440 to ten times the total bit cell capacitance of trusted memory block 140, it is ensured that once capacitor 440 is coupled to the power connection of trusted memory block 140 with reverse polarity, it has sufficient charge to neutralize the charge within the RAM bit cells of trusted memory block 140. Since the goal is to discharge the RAM bit cell charge quickly, according to one embodiment, capacitor 440 (which can be considered a decoupling capacitor) should exhibit a capacitance of at least twice the total bit cell capacitance of trusted memory block 140, as 1 times would only make it electrically neutral. Since the decoupling capacitor values are larger than the capacitors of the RAM bit cells of the trusted memory block 140, the total time constant is defined by the resistance of the second pair of switches 430a, 430b and the capacitance of the capacitor 440. In a 3τ (tau) time constant, the total charge will be neutralized up to 95% of its final value, which will be well below the threshold voltage of the transistors and thus will be difficult to detect.

[0034] Decoupling capacitor 440 is used as a battery source. In response to operation of the first pair of switches 420a, 420b and the second pair of switches 430a, 430b, the polarity is reversed at the power output of the switch matrix 210 and the resulting voltage is applied to the power connection of the trusted RAM block 140. Figure 4 and Figure 6 The embodiment shown in allows erasure of the entire trusted RAM block 140 to be achieved in a single clock cycle, which can be defined by the secure macro clock or the system clock. The timing for controlling switches 410, 420 and 430 can be separated by one or more clock cycles based on the specific implementation of the system.

[0035] The mechanisms enabled in various embodiments are not limited to secure random access memory, but can be used with any type of volatile memory in any type of system, particularly systems that may require fast erase functionality of volatile memory.

Claims

1. A memory device comprising: a switch matrix, the switch matrix comprising a power input, a control input and a power output, a random access memory having a power connection coupled to the power output of the switch matrix, wherein the switch matrix includes a capacitor capable of being charged by a power supply coupled to the power supply input, and wherein upon receiving a control signal via the control input, the switch matrix is designed to decouple the capacitor from the power supply input and the power supply output and couple the capacitor with reverse polarity via the power supply output to the random access memory.

2. The memory device of claim 1, wherein the random access memory is a secure random access memory within an embedded system. 3 . The memory device of claim 1 , wherein the switch matrix comprises a first set of switches coupling the capacitor to the power supply input and a second set of switches for coupling the capacitor to the power supply output.

4. The memory device of claim 3 , wherein the second set of switches includes a first pair of switches and a second pair of switches, the first pair of switches being configured to couple the capacitor to the power supply output with a first polarity, and the second pair of switches being configured to couple the capacitor to the power supply output with a second polarity, wherein the second polarity is an opposite polarity relative to the first polarity. 5 . The memory device of claim 4 , wherein the switch matrix is controlled to keep the first pair of switches in the first and second sets of switches closed while keeping the second pair of switches in the second set of switches open during normal operation. 6 . The memory device of claim 5 , wherein upon receiving the control signal, the switch matrix is configured to open the first pair of switches and the first group of switches in the second group of switches and then close the second pair of switches in the second group of switches. 7 . The memory device of claim 6 , wherein the switches in the second set of switches are controlled by a single switch control signal, wherein the first pair of switches are designed to operate faster than the second pair of switches.

8. The memory device of claim 6 , wherein the first pair of switches is controlled by a first switch control signal and the second pair of switches is controlled by a second switch control signal, wherein to reverse the polarity of the capacitor, the first switch control signal is configured to be asserted before the second switch control signal.

9. The memory device of claim 6, wherein switches in the first set of switches are controlled to open after the first pair of switches in the second set of switches.

10. The memory device of claim 1, wherein a capacitance of the capacitor is 10 times greater than a total bit cell capacitance of the random access memory. 11 . The memory device of claim 1 , wherein a size of a switch for coupling the capacitor in reverse polarity is set to 3τ (tau).

12. A microcontroller comprising the memory device according to claim 2, wherein the microcontroller forms an embedded system. 13 . A hardware security module coupled to the memory device according to claim 2 .

14. A method for operating a memory device, the method comprising: providing a supply voltage to a random access memory via a switch matrix, wherein the switch matrix includes a power input, a power output, and a capacitor charged by the supply voltage; receiving a control signal instructing to erase the memory, and Upon receiving the control signal for erasing the memory, the capacitor is decoupled from the power supply and the random access memory through the switch matrix, and then the capacitor is coupled to the power supply output with reverse polarity.

15. The method of claim 14, wherein the random access memory is a secure random access memory within an embedded system.

16. The method of claim 14 , wherein the switch matrix comprises a first set of switches for coupling the capacitor to the power supply input and a second set of switches for coupling the capacitor to the power supply output, wherein the second set of switches comprises a first pair of switches and a second pair of switches, the first pair of switches being configured to couple the capacitor to the power supply output with a first polarity, and the second pair of switches being configured to couple the capacitor to the power supply output with a second polarity, wherein the second polarity is an inverse polarity with respect to the first polarity. 17 . The method according to claim 16 , further comprising controlling the first pair of switches in the first and second groups of switches to be closed while keeping the second pair of switches in the second group of switches open when the control signal is not received. 18 . The method according to claim 17 , wherein when the control signal is received, the first pair of switches and the first group of switches in the second group of switches are controlled to be open, and then the second pair of switches in the second group of switches are controlled to be closed.

19. The method of claim 18, wherein the switches in the second set of switches are controlled by a single switch control signal, wherein the first pair of switches are designed to operate faster than the second pair of switches.

20. The method of claim 18, wherein the first pair of switches is controlled by a first switch control signal and the second pair of switches is controlled by a second switch control signal, wherein to reverse the polarity of the capacitor, the first switch control signal is asserted before the second switch control signal.

21. The method of claim 18, wherein switches in the first set of switches are controlled to open after the first pair of switches in the second set of switches are controlled to open.

22. The method of claim 14, wherein the capacitance of the capacitor is 10 times greater than a total bit cell capacitance of the random access memory.

23. The method of claim 14, wherein a switch for coupling the capacitor in reverse polarity is sized to 3τ (tau).

Citation Information

Patent Citations

  • Application-specific integrated circuit configured to interface with automotive diagnostic port

    US20180225249A1

  • Capacitor block comprising capacitors that can be connected to each other and method for charging and discharging the capacitors to write a phase change material memory

    WO2010078483A1