Centralized Non-Volatile Memory for Multi-Processor Firmware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Distributed server platforms with multiple application processors (APs) face vulnerabilities from flash memory limitations, including limited write cycles, wear-out due to excessive writing, and security risks from firmware attacks, which increase costs and complexity in securing supply chains and communication interfaces.
Innovation Solution
Centralizing firmware and configuration data in a non-volatile memory device, such as NVMe or eMMC, and employing a shared memory programming model with management controllers and memory management units (MMUs) to manage access and ensure security and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If each application processor has its own flash memory device, then boot support and configuration parameters can be stored locally, but the system becomes vulnerable to flash wear-out attacks and supply chain attacks, increasing security risks and costs
Solution Approach 1:
The patent merges multiple individual flash memory devices into a single shared non-volatile memory device that is commonly accessed by all application processors. This consolidation eliminates the need for separate flash memory devices for each processor, reducing the attack surface while maintaining boot support and configuration storage capabilities through a centralized memory architecture with proper access control mechanisms
2Reliability
If flash memory devices are used for storing firmware and configuration data, then local storage is enabled for each processor, but write and erase cycles are limited, making the system susceptible to wear-out from excessive writing
Solution Approach 1:
By consolidating multiple flash memory devices into a single shared non-volatile memory device with higher total write cycle capacity, the system distributes the write wear across a larger memory pool. This allows the individual application processors to access firmware and configuration data without depleting the limited write cycles of single-processor flash devices, thereby extending the effective lifespan of the memory subsystem
3Reliability
If separate external root of trust devices are coupled to flash memory devices, then security operations can be protected, but the system complexity and cost increase
Solution Approach 1:
The patent consolidates multiple external root of trust devices into a single shared security module that provides security operations for all application processors. This unified approach maintains comprehensive security protection while reducing the number of discrete security devices, thereby lowering system complexity and cost without compromising the protective functions
4Reliability
If multiple flash memory devices are deployed for different application processors, then each processor has dedicated storage, but the cost to secure supply chains and reduce attack risks becomes expensive and time-consuming
Solution Approach 1:
The patent merges multiple flash memory devices into a single shared non-volatile memory device, which simplifies supply chain security efforts. Instead of managing and securing multiple separate flash memory suppliers and components, the system uses one centralized memory device with a well-defined security model, thereby reducing the time and cost required to secure the supply chain while maintaining the necessary security protections
Data Source
AI summary
A system includes application processors (APs) at least some of which communicate over a network. The system includes a non-volatile memory device to store at least one of configuration data or firmware that is accessed by the APs. The configuration data or firmware enables operation of respective APs. The system includes a controller communicatively coupled to the APs and the non-volatile memory device. The controller is configured to centralize processing of messages received from the APs and to manage shared access to the non-volatile memory device by the APs.


