Flash Memory Security via Partial Programming and Read Disturbance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware security solutions, such as hardware random number generators and Physical Unclonable Functions, require carefully designed circuits and are not efficient in all Flash memory devices, taking long times to generate fingerprints and being tied to the Flash memory content.

Innovation Solution

The method involves partially programming Flash memory, observing characteristics resulting from this partial programming, and using these characteristics for security functions like random number generation and fingerprinting, which can be implemented in all Flash memory devices without requiring long generation times and are decoupled from the Flash memory content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional hardware random number generators are used, then true randomness is achieved, but carefully designed circuits are required and not all Flash memory devices can be used

Engineering Contradiction:
Improverandomness qualityVSAvoidcircuit design complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes standard Flash memory devices perform multiple functions including random number generation, fingerprinting, and data hiding without requiring custom circuits. By using the existing Flash memory interface and exploiting inherent physical characteristics (program time variations, read disturbances), the solution enables security functions in ubiquitous Flash devices, achieving universality across different Flash memory implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If existing fingerprinting methods using Flash memory are used, then device identification is achieved, but long processing times (100 seconds for one fingerprint) are required

Engineering Contradiction:
Improvefingerprint accuracyVSAvoidfingerprint generation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by partially programming Flash memory pages to specific threshold states before fingerprint extraction. By pre-positioning memory cells in metastable states through controlled partial programming operations, the system prepares the Flash memory to rapidly exhibit readable disturbances that encode device-specific fingerprints, significantly reducing the time required compared to waiting for natural program disturbances.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs periodic read operations after partial programming to capture transient disturbances in Flash memory cells. By repeatedly reading the partially programmed pages at specific intervals and analyzing the temporal patterns of read disturbances, the system efficiently extracts fingerprint information without requiring excessively long measurement periods.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If existing fingerprinting methods are used, then device identification is achieved, but the method relies on rare errors called program disturbs and only works for certain types of Flash chips

Engineering Contradiction:
Improvefingerprint uniquenessVSAvoidFlash memory compatibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent changes the operational parameters of Flash memory by controlling programming voltage, pulse duration, and read conditions to induce controlled disturbances in memory cells. By adjusting these parameters, the system can reliably generate readable disturbances in various Flash memory types (NAND, NOR, 3D stacked, 2D planar) without relying on rare natural program disturbs, thereby achieving broad compatibility across different Flash chip architectures.

Inventive Principle:
Principle #35Parameter changes

4Loss of information

If data is hidden in Flash memory content, then data hiding is achieved, but the hidden data is tied to the Flash memory content making it vulnerable

Engineering Contradiction:
Improvedata hiding capabilityVSAvoiddata security
Core Design Contradiction:
Loss of informationVSReliability

Solution Approach 1:

The patent extracts security-critical information (fingerprints, random numbers) from the physical characteristics of Flash memory rather than embedding data within the Flash memory content. By separating the security function from the storage content and using inherent physical properties (program time variations, read disturbances) as the security foundation, the system makes hidden data independent of Flash memory content, preventing attacks that target or modify stored data.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This approach enables efficient random number generation and fingerprinting in all Flash memory devices, providing true randomness and unique device fingerprints without the need for custom circuits or long processing times, and decouples data hiding from the Flash memory content.

Implementation Method 1

Process variation in semiconductor foundries is a common source of hardware uniqueness, which is out of the control of the designer.

Methodology Applied
Scientific EffectProcess variation:

Implementation Method 2

Thermal noise and other system level noise are the common entropy sources in recently proposed hardware random number generators.

Methodology Applied
Scientific EffectThermal noise:

Implementation Method 3

Recently, PUFs have been implemented without additional circuitry by exploiting metastable elements such as SRAM cells, which have unique value on start-up for each IC instance

Methodology Applied
Scientific EffectMetastability: Metastability

Data Source

PatentUS10078462B2Methods and systems for providing hardware security functions using flash memories
Publication Date: 2018.09.18 CORNELL UNIVERSITY
  • US10078462B2 patent drawing
  • US10078462B2 patent drawing
  • US10078462B2 patent drawing

AI summary

Methods and system for providing a security function, such as random number generation, fingerprinting and data hiding, using a Flash memory. The methods and systems do not require carefully design specific circuits, can be implemented in all flash memory device. The fingerprinting methods and systems do not require a long time to generate a read and the data hiding is decoupled from Flash memory content.