Memory Access Control Chip DMA Attack Mitigation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing PCIe interfaces are vulnerable to direct memory access (DMA) attacks, which compromise information security, and existing solutions that prevent such attacks often sacrifice performance by disabling external PCIe ports.

Innovation Solution

A control chip with a selection circuit and two transmission interfaces (UHS-I and PCIe) determines whether a memory device supports PCIe for DMA, allowing users to select the interface through a pop-up window based on permissions, thereby enabling secure access control without disabling the PCIe interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If the PCIe interface is enabled for external device access, then transmission speed and performance are improved, but information security deteriorates due to DMA attack vulnerabilities

Engineering Contradiction:
Improvetransmission speedVSAvoidDMA attack vulnerability
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The system dynamically switches between PCIe and UHS-I interfaces based on real-time security conditions and user preferences. The control chip can adaptively select the appropriate transmission interface, making the system flexible rather than static. This resolves the contradiction by allowing high-speed PCIe transmission when safe and falling back to secure UHS-I when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The control chip acts as an intermediary between the host device and memory device, mediating the transmission interface selection. It receives capability information from the memory device, determines whether PCIe is supported, and controls which interface is used for communication. This intermediary function enables security control without sacrificing PCIe performance benefits.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If the external PCIe port is removed to prevent DMA attacks, then information security is improved, but the advantages of PCIe interface are lost

Engineering Contradiction:
ImproveDMA attack preventionVSAvoidPCIe interface functionality
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The control chip is designed with multi-functionality, supporting both PCIe and UHS-I interfaces. This universal design allows the system to utilize PCIe capabilities when available and secure when UHS-I is used. The memory device itself also supports dual interfaces, enabling flexible adaptation to different security requirements while maintaining performance benefits.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the transmission interface parameter based on security conditions and device capabilities. Instead of permanently disabling PCIe, the system dynamically adjusts which interface is active, changing the transmission mode parameter from PCIe to UHS-I or vice versa. This parameter flexibility resolves the contradiction between security and functionality.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If automatic interface selection is implemented, then ease of operation is improved, but user control over security decisions is reduced

Engineering Contradiction:
Improveautomatic interface selectionVSAvoiduser control over security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback by notifying users of the selected transmission interface through pop-up windows. Users receive information about whether PCIe or UHS-I is being used and can provide feedback by confirming or changing the selection. This feedback loop maintains user awareness and control while still providing automatic selection convenience.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The control chip automatically determines interface capabilities and makes initial selection decisions without requiring user intervention. The system serves itself by autonomously evaluating memory device capabilities and selecting the appropriate interface, while still allowing user override when needed. This self-service approach balances automation with user control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11221969B2Method and control chip for performing access control of memory device
Publication Date: 2022.01.11 REALTEK SEMICON CORP
  • US11221969B2 patent drawing
  • US11221969B2 patent drawing
  • US11221969B2 patent drawing

AI summary

A method and a control chip for performing access control of a memory device are provided, wherein the control chip is coupled to a host device. The method includes: utilizing a first transmission interface of the control chip to determine whether the memory device supports a second transmission interface different from the first transmission interface to generate a determination result; and according to user permissions of a user regarding the host device, determining whether to allow the control chip to decide whether to utilize the second transmission interface to access the memory device based on the determination result. In addition, if the user permissions satisfy a predetermined condition, a user interface of the host device may display a pop-up window in order to allow the user to decide which one of the first transmission interface and the second transmission interface to utilize for accessing the memory device.