Memory Attack Detection Module for DMA Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data processing systems are vulnerable to direct memory access attacks, where attackers bypass the processing core to access memory directly, compromising system security by extracting sensitive information or corrupting memory.
Innovation Solution
A memory attack detection module (MADM) is integrated into the memory controller to detect rogue signals on the memory bus, identifying and responding to unauthorized access attempts by generating indicators and triggering remedial actions such as system reboot or power shutdown.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If direct memory access (DMA) is enabled to allow subsystems to access memory without the processing core, then system productivity and ease of operation are improved, but system security and reliability deteriorate due to vulnerability to DMA attacks
Solution Approach 1:
The patent introduces a memory attack detection module (MADM) as an intermediary component between the memory controller and the memory system. This MADM monitors and detects unauthorized access attempts on the memory bus, allowing DMA functionality to remain enabled for productivity while providing security oversight to prevent attacks. The MADM acts as a mediator that permits legitimate DMA operations while blocking malicious ones.
2Use of energy by moving object
If the system enters inactive states like S3 sleep mode to conserve energy, then use of energy is improved, but security vulnerability increases because the memory remains accessible during inactive states
Solution Approach 1:
The patent implements preliminary detection actions before the system fully enters inactive states. The MADM continuously monitors the memory bus even during transition to sleep mode and can detect attack attempts before they can compromise the system. This preliminary monitoring ensures that energy-saving states do not create security vulnerabilities, as attacks are detected and prevented before the system becomes vulnerable during inactive states.
3Reliability
If comprehensive memory bus monitoring is implemented to detect all unauthorized access attempts, then system security is improved, but device complexity and measurement difficulty increase
Solution Approach 1:
The patent implements local quality monitoring by focusing the MADM's detection capabilities on specific critical signals and access patterns on the memory bus rather than monitoring every possible signal uniformly. The MADM selectively monitors key memory bus transactions and unauthorized access indicators, providing comprehensive security coverage while maintaining manageable system complexity through targeted rather than exhaustive monitoring.
Data Source
AI summary
A data processing system includes technology to detect a memory attack. The data processing system comprises a processing core, a memory controller, a memory bus, and memory. The memory controller comprises a memory attack detection module (MADM). The MADM comprises first and second input units and control logic in communication with the first and second input units. The control logic is configured to determine, based on first and second signals from the first and second input units, respectively, whether the memory bus is carrying a clock enable (CKE) signal of high (H), even though the memory controller is generating the CKE signal of low (L). The control logic is also configured to generate a physical memory attack detection indicator that indicates whether the memory bus is carrying the CKE signal of H, even though the memory controller is generating the CKE signal of L. Other embodiments are described and claimed.


