Integrated Security Processor in Memory Subsystem
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Network-based systems face challenges in integrating robust security measures due to limited processing capability and resource constraints, making them vulnerable to unauthorized data interception and corruption, which existing security schemes are unable to effectively address.
Innovation Solution
A memory module with a security processor integrated into an embedded memory subsystem that stores security software and controls non-volatile memory, allowing concurrent processing of security protocols while the host processor handles normal functions, thereby optimizing processor/memory utilization and ensuring a heightened level of security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security processor is integrated into the memory subsystem, then security functionality and protection against unauthorized access are improved, but device complexity increases
Solution Approach 1:
The patent integrates the security processor directly into the memory subsystem by coupling it to the memory controller, creating a unified security-enhanced memory device. This merging approach improves security functionality while managing complexity through integration rather than separate components
Solution Approach 2:
The memory controller serves as an intermediary between the host processor, volatile memory, and non-volatile memory, while the security processor monitors and controls access through this controller. This intermediary structure enables security functionality without requiring direct complex interactions between all components
2Reliability
If extensive security computations are performed, then security protection is improved, but processing capability requirements increase
Solution Approach 1:
The patent divides processing responsibilities by separating security computations from normal host processor operations. The security processor handles security protocols and computations independently, while the host processor focuses on application tasks, thus improving security protection without overburdening the host processor's processing capability
Solution Approach 2:
The security processor autonomously performs security computations and protocols without requiring extensive host processor intervention. It independently monitors memory access, validates security credentials, and manages cryptographic operations, enabling robust security protection with minimal impact on host processor processing capability
3Device complexity
If the host processor handles security functions, then security implementation is simplified, but system performance and productivity decrease
Solution Approach 1:
The patent segments security functions from normal processor operations by introducing a dedicated security processor. This segmentation simplifies security implementation by providing specialized hardware for security tasks while maintaining high system performance through parallel operation of security and application processing
Solution Approach 2:
The security processor operates continuously and independently to monitor memory access and execute security protocols without interrupting host processor operations. This continuous parallel operation enables simplified security implementation while maintaining optimal system performance and productivity
Data Source
AI summary
An architecture is presented that facilitates integrated security capabilities. A memory module is provided that comprises non-volatile memory that stores security software and a security processor that accesses the security software from the nonvolatile memory and performs security functions based on the security software stored. Further, a host processor located outside of the memory module arbitrates with the security processor for access to the non-volatile memory. The memory module in communication with the host processor establishes a heightened level of security that can be utilized in authentication services and secure channel communications.


