DRAM Security Mechanism Using Counter-Compare Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional semiconductor memory devices lack effective security mechanisms to prevent unauthorized access at the device/component level, allowing nefarious devices to gain access by simulating legitimate interactions and exploiting silent controller states, leading to potential data breaches.

Innovation Solution

Incorporating a security mechanism with a counter-compare circuit to track targeted commands and a timer-compare circuit to track duration, which sends authentication commands before a predetermined threshold is reached, ensuring that only authorized access is allowed by generating errors for unauthorized interactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional semiconductor memory devices are used without security mechanisms, then device complexity is reduced and ease of manufacture is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security mechanism is segmented into distinct functional modules: an authentication circuit with separate counter-compare and timer-compare circuits, each handling specific authentication tasks. This segmentation allows the security function to be integrated without overwhelming complexity, as each module operates independently with a specific role in the authentication process.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication circuit performs preliminary authentication checks by tracking commanded operations and time durations before allowing memory access. The counter-compare circuit pre-establishes a threshold for commanded operations, and the timer-compare circuit pre-establishes a time window, both preparing authentication criteria in advance to prevent unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication commands are sent frequently to ensure security, then security reliability is improved, but productivity deteriorates due to increased overhead

Engineering Contradiction:
ImprovesecurityVSAvoidproductivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The authentication mechanism operates periodically by monitoring the count of commanded operations and elapsed time, triggering authentication checks at predetermined intervals rather than continuously. The counter-compare circuit triggers authentication when a threshold number of commands are issued, and the timer-compare circuit triggers when a time duration is reached, creating periodic authentication opportunities that balance security with performance.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication circuit performs self-service by autonomously tracking commanded operations and time durations, comparing these against predetermined thresholds, and generating authentication commands without requiring constant external intervention. This self-managing capability reduces the overhead on the memory controller while maintaining continuous security monitoring.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11074201B2Apparatus with a security mechanism and methods for operating the same
Publication Date: 2021.07.27 MICRON TECHNOLOGY INC
  • US11074201B2 patent drawing
  • US11074201B2 patent drawing
  • US11074201B2 patent drawing

AI summary

Methods, apparatuses and systems related to managing access to a memory device are described. A dynamic random access memory (DRAM) device may limit or restrict access. In some cases, a memory device may be operated in a secure mode following issuance of a sequence of commands or based on a certain timing (e.g., based on clock cycles or an oscillator). A mode register of the memory device may be used to enable or disable certain modes of operation, including secure modes of operation. In some examples, a memory device may operation in an idle state while in a secure mode, and it may ignore (e.g., take no action in response to) certain commands while in the idle mode. A device may ignore commands if it identifies a mismatch in clock cycles or oscillator frequency, including when moved from one system to another without prior authentication or orderly shutdown.