Memory Access Control Chip DMA Attack Mitigation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing PCIe interfaces are vulnerable to direct memory access (DMA) attacks, which compromise information security, and existing solutions that prevent such attacks often sacrifice performance by disabling external PCIe ports.
Innovation Solution
A control chip with a selection circuit and two transmission interfaces (UHS-I and PCIe) determines whether a memory device supports PCIe for DMA, allowing users to select the interface through a pop-up window based on permissions, thereby enabling secure access control without disabling the PCIe interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If the PCIe interface is enabled for external device access, then transmission speed and performance are improved, but information security deteriorates due to DMA attack vulnerabilities
Solution Approach 1:
The system dynamically switches between PCIe and UHS-I interfaces based on real-time security conditions and user preferences. The control chip can adaptively select the appropriate transmission interface, making the system flexible rather than static. This resolves the contradiction by allowing high-speed PCIe transmission when safe and falling back to secure UHS-I when needed.
Solution Approach 2:
The control chip acts as an intermediary between the host device and memory device, mediating the transmission interface selection. It receives capability information from the memory device, determines whether PCIe is supported, and controls which interface is used for communication. This intermediary function enables security control without sacrificing PCIe performance benefits.
2Object-affected harmful factors
If the external PCIe port is removed to prevent DMA attacks, then information security is improved, but the advantages of PCIe interface are lost
Solution Approach 1:
The control chip is designed with multi-functionality, supporting both PCIe and UHS-I interfaces. This universal design allows the system to utilize PCIe capabilities when available and secure when UHS-I is used. The memory device itself also supports dual interfaces, enabling flexible adaptation to different security requirements while maintaining performance benefits.
Solution Approach 2:
The system changes the transmission interface parameter based on security conditions and device capabilities. Instead of permanently disabling PCIe, the system dynamically adjusts which interface is active, changing the transmission mode parameter from PCIe to UHS-I or vice versa. This parameter flexibility resolves the contradiction between security and functionality.
3Ease of operation
If automatic interface selection is implemented, then ease of operation is improved, but user control over security decisions is reduced
Solution Approach 1:
The system implements feedback by notifying users of the selected transmission interface through pop-up windows. Users receive information about whether PCIe or UHS-I is being used and can provide feedback by confirming or changing the selection. This feedback loop maintains user awareness and control while still providing automatic selection convenience.
Solution Approach 2:
The control chip automatically determines interface capabilities and makes initial selection decisions without requiring user intervention. The system serves itself by autonomously evaluating memory device capabilities and selecting the appropriate interface, while still allowing user override when needed. This self-service approach balances automation with user control.
Data Source
AI summary
A method and a control chip for performing access control of a memory device are provided, wherein the control chip is coupled to a host device. The method includes: utilizing a first transmission interface of the control chip to determine whether the memory device supports a second transmission interface different from the first transmission interface to generate a determination result; and according to user permissions of a user regarding the host device, determining whether to allow the control chip to decide whether to utilize the second transmission interface to access the memory device based on the determination result. In addition, if the user permissions satisfy a predetermined condition, a user interface of the host device may display a pop-up window in order to allow the user to decide which one of the first transmission interface and the second transmission interface to utilize for accessing the memory device.


