Embedded NVRAM Secure Boot Processor Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer systems' security is vulnerable to attacks due to the separation of the processor and flash memory, which allows malicious software to compromise boot-up and BIOS components, and the limited programmable fuse space hinders effective secure boot processes.
Innovation Solution
Integration of a significant amount of embedded non-flash non-volatile random access memory (NVRAM) onto the processor semiconductor chip to store boot-up and BIOS program code modules, replacing traditional flash memory and fuse technology, enhancing security by reducing the risk of separate chip attacks and providing increased storage capacity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If flash memory is used to store boot-up and BIOS program code modules, then storage capacity is sufficient, but security is vulnerable to attacks due to separation from processor
Solution Approach 1:
The patent merges the processor and flash memory onto a single semiconductor chip, creating an integrated system where the boot-up and BIOS program code modules are stored directly on the processor chip. This eliminates the physical separation between processor and memory, thereby enhancing security by preventing external attacks on separate memory components while maintaining sufficient storage capacity.
2Reliability
If programmable fuse space is used for secure boot processes, then security validation is enabled, but storage capacity is limited
Solution Approach 1:
The patent combines programmable fuse space with additional secure storage resources on the same chip, creating a hybrid storage system that provides both the security validation capabilities of fuses and the extended storage capacity needed for comprehensive boot process security.
Solution Approach 2:
The integrated memory system serves multiple functions: it stores boot-up program code modules, BIOS program code modules, and provides secure storage for cryptographic keys and validation data, thereby enabling comprehensive secure boot processes with sufficient storage capacity.
3Ease of manufacture
If separate flash memory chip is used, then manufacturing is easier, but security risk increases due to separate chip attacks
Solution Approach 1:
The patent integrates flash memory and processor onto a single semiconductor chip using advanced manufacturing processes, thereby maintaining manufacturing feasibility while eliminating the security vulnerabilities associated with separate memory chips. The integrated design allows both components to be fabricated together in the same production line.
4Productivity
If traditional separate memory architecture is used, then data transfer is simpler, but boot time is slower due to off-chip communication
Solution Approach 1:
The patent merges the flash memory and processor onto the same die, enabling on-die data transfer between the boot-up and BIOS program code modules and the processor. This eliminates the need for off-chip communication during boot operations, significantly reducing boot time while the integrated architecture manages the complexity through unified memory control.
Data Source
AI summary
A processor semiconductor chip is described. The processor semiconductor chip includes at least one processing core. The processor semiconductor chip also includes a memory controller. The processor semiconductor chip also includes an embedded non flash non-volatile random access memory having a stack of storage cells disposed above the processor semiconductor chip's semiconductor substrate. The embedded non-volatile random access memory is to store boot up program code that, when executed by the processor semiconductor chip, is to analyze a subsequent module of program code so that a maliciously modified version of the subsequent module of program code can be identified. The embedded non-volatile random access memory to also store the subsequent module of program code.


