Memory Access Controller for Selective Security Activation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Security systems, such as those on chip cards, face increased chip area and energy consumption due to existing digital mechanisms for error detection and prevention, which are inefficient in managing energy usage during non-security-critical operations.
Innovation Solution
Implementing a memory access controller with dual executing units and checkers to differentiate between critical and uncritical software segments, activating security mechanisms only during security-critical operations, thereby reducing energy consumption by using hardware redundancy selectively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital mechanisms for error detection and hardware redundancy are continuously activated, then security against error attacks is improved, but energy consumption increases
Solution Approach 1:
The patent implements dynamic activation of security mechanisms by introducing a memory access controller that selectively enables or disables access to critical software portions based on runtime conditions. The controller receives access requests and dynamically controls whether the second executing unit (with redundancy) is activated, allowing the system to adapt between high-security and low-power modes rather than maintaining constant security protection.
Solution Approach 2:
The patent applies security mechanisms locally only to critical software portions rather than uniformly across all software. The memory is divided into segments with critical portions stored in specific address ranges, and the access controller selectively applies redundancy checks only when accessing these critical segments, leaving non-critical areas to operate without the overhead of continuous security monitoring.
2Reliability
If hardware redundancy is continuously activated, then error attack prevention is improved, but chip area increases
Solution Approach 1:
The patent implements dynamic activation of the second executing unit based on access requests to critical software portions. The memory access controller monitors each access request and only activates the redundant executing unit when a request targets a critical segment, allowing the system to minimize the active chip area while maintaining security when needed.
Solution Approach 2:
The patent applies redundancy locally only to critical software portions by segmenting the memory and using address range checking. The first checker analyzes the address of each access request to determine if it targets a critical segment, and only then does the system engage the second executing unit for redundant execution, keeping the redundant hardware in a standby state for non-critical operations.
3Reliability
If security mechanisms are continuously activated, then protection against attacks is improved, but energy consumption increases
Solution Approach 1:
The patent implements dynamic security activation through the memory access controller that responds to access requests in real-time. When an access request targets a non-critical software portion, the controller keeps security mechanisms deactivated, minimizing energy loss. Only when a request targets a critical segment does the controller activate the second executing unit and associated checkers, thereby dynamically adjusting energy consumption to actual security needs.
Solution Approach 2:
The patent applies security mechanisms locally to only those memory segments containing critical software portions. The first checker examines the address of each access request and compares it against defined address ranges for critical segments. Security checks and redundant execution are applied only when the address falls within a critical segment range, avoiding unnecessary energy consumption for non-critical areas.
Data Source
AI summary
A memory access controller has a first interface connectable to a memory and a second interface coupled with a first and a second executing unit. A critical software portion is stored in a first segment of the memory, and an uncritical software portion is stored in a second segment of the memory. The critical and uncritical software portions are executed by the first executing unit, and the critical software portion is additionally executed by the second executing unit. The memory access controller further has a first checker having an input for an access request received via the second interface and an output for a first check signal indicating whether the access request is directed to the first segment. Furthermore, the memory access controller has a second checker having an output for a second check signal indicating whether the second executing unit is active, as well as a control unit having inputs for the first and second check signals and an output for an alarm signal indicating that the access request is directed to the first segment and the second executing unit is not active.


