Cryptographic Memory Intrusion Detection and Data Removal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for securing cryptographic systems against cold boot and side channel attacks are inadequate, as they primarily focus on perimeter security and hardware modifications, failing to effectively protect cryptographic data in memory from physical breaches.

Innovation Solution

A software application that detects intrusion signals and responds by removing cryptographic data from memory, either by flushing or overwriting it, and optionally dismounting storage devices to ensure data integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic data is stored in memory for system operation, then system functionality is maintained, but vulnerability to cold boot attacks increases

Engineering Contradiction:
Improvesystem functionalityVSAvoidvulnerability to cold boot attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary actions by detecting intrusion signals before attackers can access cryptographic data in memory, and by proactively removing the data or rendering it unrecoverable before the attack completes. The system monitors for physical access attempts and preemptively secures the data by clearing memory contents or making them不可恢复

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by implementing countermeasures that oppose the cold boot attack mechanism. When intrusion is detected, the system actively counteracts the attack by removing cryptographic data from memory or rendering it unrecoverable, thereby neutralizing the threat before the attacker can cool the memory and extract keys

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If cryptographic data is removed from memory upon intrusion detection, then security is improved, but system functionality is disrupted

Engineering Contradiction:
ImprovesecurityVSAvoidsystem functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamics by making the memory contents dynamic rather than static. Cryptographic data in memory is transformed from a persistent state to a transient state that can be rapidly cleared or rendered unrecoverable in response to intrusion detection signals, allowing the system to adapt its security posture in real-time

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies segmentation by separating the cryptographic data storage from permanent storage and keeping it in volatile memory that can be independently cleared. The system divides memory management into segments that can be selectively cleared based on intrusion detection, allowing partial or complete memory flushing without affecting the entire system

Inventive Principle:
Principle #1Segmentation

3Reliability

If physical access controls are implemented, then perimeter security is improved, but protection against determined attackers is insufficient

Engineering Contradiction:
Improveperimeter securityVSAvoidprotection against determined attackers
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary layer of software-based intrusion detection and response that sits between the physical hardware and the cryptographic data. This intermediary monitors for physical access attempts and intermediates the protection by detecting intrusion signals and triggering automated responses to remove or secure cryptographic data, adding a layer of defense that operates independently of physical security measures

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10726163B2Protecting cryptographic systems from cold boot and other side channel attacks
Publication Date: 2020.07.28 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10726163B2 patent drawing
  • US10726163B2 patent drawing
  • US10726163B2 patent drawing

AI summary

An electrical signal indicative of an intrusion is detected at an application executing in a cryptographic data processing system. In response to the detection, an instruction is constructed in the application for the cryptographic data processing system. Using a processor, the instruction causes a cryptographic data item to be removed from a portion of a memory device installed in the cryptographic system.