Integrated Circuit Memory Security via Unified Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cyberattacks on data centers are increasing in sophistication, with attackers disrupting communication networks by eavesdropping on management messages, sending malicious packets, and exploiting protocols like Precision Time Protocol (PTP). Existing solutions like end-to-end encryption and MACsec do not adequately protect sensitive information and network security keys from unauthorized access.
Innovation Solution
An integrated circuit (IC) chip architecture that provides a processor external to the IC chip with unsecured access to first memories and secured access to second memories via a single communication interface. The IC chip includes embedded hardware security circuitry to authenticate the processor and provide secure access to the secured memories, while limiting unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If separate communication interfaces are used for secure and unsecured access, then security is improved, but device complexity and pin counts increase
Solution Approach 1:
The patent combines secure and unsecured access functions into a single communication interface. The interconnect circuitry selectively routes traffic from this unified interface to appropriate memory regions based on security requirements, eliminating the need for separate physical interfaces while maintaining security boundaries.
Solution Approach 2:
The interconnect circuitry acts as an intermediary between the single communication interface and the memory system. It receives access requests from the processor, determines whether they target secure or unsecured memory regions, and selectively grants or blocks access accordingly, thus mediating security without requiring separate interfaces.
2Reliability
If separate communication interfaces are used for secure and unsecured access, then security is improved, but chip area increases
Solution Approach 1:
The patent merges secure and unsecured access pathways into a single communication interface structure on the chip. This consolidation reduces the total chip area required compared to implementing separate physical interfaces, while the interconnect circuitry maintains security through selective access control to different memory regions.
3Reliability
If direct access to second memory is blocked, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The interconnect circuitry serves as an intelligent intermediary that automatically determines whether to grant or block access to the second (secure) memory based on the processor's authentication status and the memory address being accessed. This automated mediation maintains security without requiring manual intervention or complex operational procedures from the user.
Solution Approach 2:
The system implements self-service security where the interconnect circuitry autonomously handles access control decisions. The processor simply issues memory access requests through the single interface, and the interconnect circuitry automatically enforces security policies by blocking unauthorized access to secure memory regions without requiring additional user actions.
Data Source
AI summary
An integrated circuit (IC) chip includes a first memory that stores first information, and a second memory that stores second information that it to be protected from unauthorized access. Communication interface circuitry gives a processor external to the IC chip read access and/or write access to components of the IC chip. Embedded hardware security circuitry selectively provides the processor external to the IC chip with secure access to the second memory. Interconnect circuitry i) selectively grants the processor unsecured access to the first memory via the communication interface circuitry, ii) selectively grants the processor access to the embedded hardware security, and iii) limits access to the second memory.


