DRAM Input Change Detection for Cold Boot Attack Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Memory devices, particularly DRAM, are vulnerable to attacks such as cold boot attacks where an attacker physically removes or modifies them to gain access to secure information, and existing protection mechanisms fail when disconnected from the CPU.

Innovation Solution

Incorporating a detection circuit within the DRAM to monitor voltage and clock speed changes, allowing it to detect potential attacks even when disconnected, and trigger protective measures like locking access or deleting data if threshold changes are detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing protection mechanisms are used, then data security is maintained during normal operation, but protection fails when the memory device is disconnected from the CPU

Engineering Contradiction:
Improvedata securityVSAvoidprotection capability when disconnected
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The memory device performs self-detection of attacks and self-protection by autonomously monitoring its own operational parameters (voltage, temperature, clock speed) and executing protective actions without external CPU intervention when disconnection is detected

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary detection of attack conditions by continuously monitoring operational parameters before actual data theft can occur, and preemptively executes protective actions to prevent unauthorized access

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a detection circuit is added to monitor voltage and clock speed changes, then attack detection capability is improved, but device complexity increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidcircuit complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The detection circuit leverages existing operational parameter monitoring infrastructure (voltage, temperature, clock speed sensors already present in the memory device) to perform attack detection, rather than adding completely new dedicated detection hardware

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system detects attacks by monitoring changes in operational parameters (voltage fluctuations, temperature changes, clock speed variations) that occur during attack scenarios, using parameter variation analysis rather than direct attack signature detection

Inventive Principle:
Principle #35Parameter changes

3Reliability

If protective measures are triggered immediately upon detecting input changes, then data security is enhanced, but false positives may increase

Engineering Contradiction:
Improvedata securityVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system uses feedback loops to continuously compare current operational parameters with historical baseline data, detecting deviations that indicate attacks while filtering out normal operational variations through iterative validation

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The protection threshold and response behavior are dynamically adjusted based on the severity and persistence of detected anomalies, allowing the system to adapt its sensitivity and avoid premature protection triggers for minor fluctuations

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12518002B2Voltage input and clock speed change determination to detect attack
Publication Date: 2026.01.06 MICRON TECHNOLOGY INC
  • US12518002B2 patent drawing
  • US12518002B2 patent drawing
  • US12518002B2 patent drawing

AI summary

Methods, systems, and devices for voltage input and clock speed change determination to detect an attack are described. In some systems, a memory device may receive first signaling indicative of a first value for an input (e.g., voltage input, clock speed) to the memory device. The memory device may further receive second signaling indicative of a second (e.g., time-delayed) value for the input to the memory device. The memory device may detect a change to the input based on the first signaling and the second signaling. For example, the memory device may compare the first signaling to the second signaling, may compare a difference between the first signaling and the second signaling to a threshold, or both. If the input changes (e.g., by a threshold amount), the memory device may disable one or more features to protect against an attack on the memory device.