DRAM Input Change Detection for Cold Boot Attack Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Memory devices, particularly DRAM, are vulnerable to attacks such as cold boot attacks where an attacker physically removes or modifies them to gain access to secure information, and existing protection mechanisms fail when disconnected from the CPU.
Innovation Solution
Incorporating a detection circuit within the DRAM to monitor voltage and clock speed changes, allowing it to detect potential attacks even when disconnected, and trigger protective measures like locking access or deleting data if threshold changes are detected.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing protection mechanisms are used, then data security is maintained during normal operation, but protection fails when the memory device is disconnected from the CPU
Solution Approach 1:
The memory device performs self-detection of attacks and self-protection by autonomously monitoring its own operational parameters (voltage, temperature, clock speed) and executing protective actions without external CPU intervention when disconnection is detected
Solution Approach 2:
The system performs preliminary detection of attack conditions by continuously monitoring operational parameters before actual data theft can occur, and preemptively executes protective actions to prevent unauthorized access
2Reliability
If a detection circuit is added to monitor voltage and clock speed changes, then attack detection capability is improved, but device complexity increases
Solution Approach 1:
The detection circuit leverages existing operational parameter monitoring infrastructure (voltage, temperature, clock speed sensors already present in the memory device) to perform attack detection, rather than adding completely new dedicated detection hardware
Solution Approach 2:
The system detects attacks by monitoring changes in operational parameters (voltage fluctuations, temperature changes, clock speed variations) that occur during attack scenarios, using parameter variation analysis rather than direct attack signature detection
3Reliability
If protective measures are triggered immediately upon detecting input changes, then data security is enhanced, but false positives may increase
Solution Approach 1:
The system uses feedback loops to continuously compare current operational parameters with historical baseline data, detecting deviations that indicate attacks while filtering out normal operational variations through iterative validation
Solution Approach 2:
The protection threshold and response behavior are dynamically adjusted based on the severity and persistence of detected anomalies, allowing the system to adapt its sensitivity and avoid premature protection triggers for minor fluctuations
Data Source
AI summary
Methods, systems, and devices for voltage input and clock speed change determination to detect an attack are described. In some systems, a memory device may receive first signaling indicative of a first value for an input (e.g., voltage input, clock speed) to the memory device. The memory device may further receive second signaling indicative of a second (e.g., time-delayed) value for the input to the memory device. The memory device may detect a change to the input based on the first signaling and the second signaling. For example, the memory device may compare the first signaling to the second signaling, may compare a difference between the first signaling and the second signaling to a threshold, or both. If the input changes (e.g., by a threshold amount), the memory device may disable one or more features to protect against an attack on the memory device.


