DRAM Unique ID Verification for Memory Tamper Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory devices, particularly volatile types like DRAM, are susceptible to attacks where unauthorized users can modify or remove them to access secure information, and existing methods lack effective means to detect such attacks in real-time.
Innovation Solution
Implementing a unique identifier (ID) for volatile memory devices, stored in non-volatile memory, which allows the host device to verify the integrity of the memory by comparing the stored ID with the actual device ID during boot-up or periodic checks, and disable features if a change is detected, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If volatile memory devices are used for high-speed data storage, then productivity is improved, but reliability deteriorates due to susceptibility to attacks and inability to detect unauthorized modifications
Solution Approach 1:
The patent applies preliminary action by storing a unique identifier in non-volatile memory before the volatile memory can be attacked or modified. This pre-stored identifier serves as a reference for future verification, allowing the system to detect unauthorized changes before they compromise security. The unique ID is established in advance during manufacturing or initialization, creating a baseline for integrity verification.
Solution Approach 2:
The patent implements feedback through a verification process that compares the stored unique identifier with the current device identifier. This feedback mechanism continuously monitors the volatile memory's integrity by checking whether the device has been replaced or tampered with, providing real-time security validation that maintains reliability while using high-speed volatile storage.
2Reliability
If verification procedures are implemented to detect attacks, then reliability is improved, but device complexity increases due to additional verification components and processes
Solution Approach 1:
The patent extracts the verification functionality into a separate, dedicated process that operates independently from the main volatile memory operations. By isolating the verification logic into distinct verification components or firmware routines, the system achieves reliable attack detection without significantly complicating the core memory storage and retrieval operations. The verification is performed as a separate check rather than being integrated into every memory access.
Solution Approach 2:
The unique identifier acts as an intermediary element that bridges the volatile memory and the verification process. This intermediate identifier stored in non-volatile memory serves as a reference point that simplifies the verification mechanism, allowing the system to check memory integrity through a single comparison operation rather than requiring complex monitoring of all memory operations.
3Reliability
If unique identifier verification is performed during boot-up and periodically, then reliability is improved through attack detection, but loss of time increases due to additional verification steps
Solution Approach 1:
The patent applies partial action by performing verification at strategically selected moments (boot-up and periodic intervals) rather than continuously during every operation. This approach provides sufficient security verification to detect attacks while minimizing the time lost to verification processes. The verification is performed only when necessary to maintain security, rather than at every possible opportunity.
4Reliability
If non-volatile memory is used to store unique identifier, then reliability is improved through persistence, but use of energy increases compared to volatile memory only
Solution Approach 1:
The patent applies local quality by using non-volatile memory only for storing the unique identifier while maintaining volatile memory for all other data operations. This localized use of non-volatile memory provides the necessary persistence and reliability for security verification without requiring the entire system to operate at the higher energy consumption level of non-volatile storage. The system optimizes energy usage by matching the memory type to the specific requirements of each function.
Data Source
AI summary
Methods, systems, and devices for verification of a volatile memory, such as a dynamic random-access memory (DRAM), using a unique identifier (ID) are described. A memory device may store a unique ID for a DRAM component of the memory device in non-volatile memory (e.g., in the DRAM, external to the DRAM). A host device coupled with the memory device may store, to non-volatile memory at the host device, information for verifying the identity of the DRAM component, for example, based on the unique ID. The memory device and host device may perform a procedure for verification of the identity of the DRAM component using the unique ID of the DRAM and the verification information stored at the host device. If the host device detects that the DRAM has been replaced or modified based on the verification procedure, the host device may disable one or more features of the memory device.


