Integrated Circuit Memory Security via Unified Interface

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cyberattacks on data centers are increasing in sophistication, with attackers disrupting communication networks by eavesdropping on management messages, sending malicious packets, and exploiting protocols like Precision Time Protocol (PTP). Existing solutions like end-to-end encryption and MACsec do not adequately protect sensitive information and network security keys from unauthorized access.

Innovation Solution

An integrated circuit (IC) chip architecture that provides a processor external to the IC chip with unsecured access to first memories and secured access to second memories via a single communication interface. The IC chip includes embedded hardware security circuitry to authenticate the processor and provide secure access to the secured memories, while limiting unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If separate communication interfaces are used for secure and unsecured access, then security is improved, but device complexity and pin counts increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines secure and unsecured access functions into a single communication interface. The interconnect circuitry selectively routes traffic from this unified interface to appropriate memory regions based on security requirements, eliminating the need for separate physical interfaces while maintaining security boundaries.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The interconnect circuitry acts as an intermediary between the single communication interface and the memory system. It receives access requests from the processor, determines whether they target secure or unsecured memory regions, and selectively grants or blocks access accordingly, thus mediating security without requiring separate interfaces.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate communication interfaces are used for secure and unsecured access, then security is improved, but chip area increases

Engineering Contradiction:
ImprovesecurityVSAvoidchip area
Core Design Contradiction:
ReliabilityVSArea of stationary object

Solution Approach 1:

The patent merges secure and unsecured access pathways into a single communication interface structure on the chip. This consolidation reduces the total chip area required compared to implementing separate physical interfaces, while the interconnect circuitry maintains security through selective access control to different memory regions.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If direct access to second memory is blocked, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The interconnect circuitry serves as an intelligent intermediary that automatically determines whether to grant or block access to the second (secure) memory based on the processor's authentication status and the memory address being accessed. This automated mediation maintains security without requiring manual intervention or complex operational procedures from the user.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service security where the interconnect circuitry autonomously handles access control decisions. The processor simply issues memory access requests through the single interface, and the interconnect circuitry automatically enforces security policies by blocking unauthorized access to secure memory regions without requiring additional user actions.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250086297A1Secure access to memory in an integrated circuit
Publication Date: 2025.03.13 MARVELL ISRAEL (M L S L) LTD
  • US20250086297A1 patent drawing
  • US20250086297A1 patent drawing
  • US20250086297A1 patent drawing

AI summary

An integrated circuit (IC) chip includes a first memory that stores first information, and a second memory that stores second information that it to be protected from unauthorized access. Communication interface circuitry gives a processor external to the IC chip read access and/or write access to components of the IC chip. Embedded hardware security circuitry selectively provides the processor external to the IC chip with secure access to the second memory. Interconnect circuitry i) selectively grants the processor unsecured access to the first memory via the communication interface circuitry, ii) selectively grants the processor access to the embedded hardware security, and iii) limits access to the second memory.