Memory Boot Protection Against Fault Injection Reset Bypass

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Memory devices in electronic systems are vulnerable to attacks that compromise secure information, and existing protective measures can be easily bypassed by resetting the device before fault detection, allowing unauthorized access.

Innovation Solution

Implementing a default start-up delay and data erasure mechanisms in memory devices that apply a delay during boot-up if a fault is detected, combined with non-volatile penalty bit management to ensure the delay is enforced, and using stream ciphers for encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a fault detection mechanism is implemented to detect attacks on the memory device, then security is improved, but the device can be bypassed by resetting before fault detection occurs

Engineering Contradiction:
ImprovesecurityVSAvoidtime to detect fault
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by setting a penalty bit to a first value (indicating delayed start-up should occur) before fault detection. This ensures that even if an attacker resets the device before fault detection, the delayed start-up penalty is already in place and cannot be bypassed. The penalty bit is set in advance during normal operation when no attack is detected, creating a pre-condition that protects against timing-based bypass attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent inverts the conventional approach by defaulting to a delayed start-up penalty and only removing it when no attack is detected. Instead of applying delay only when faults are detected, the system assumes delay is needed and removes it only under secure conditions. This inversion ensures that the security measure remains active unless proven safe to remove, preventing bypass attacks.

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If a delayed start-up penalty is applied to slow down attacks, then security is improved, but normal boot-up time increases

Engineering Contradiction:
ImprovesecurityVSAvoidboot-up time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies dynamics by making the start-up penalty dynamic rather than static. The penalty bit can be set to either a first value (indicating delayed start-up) or a second value (indicating normal start-up) based on security conditions. When no attack is detected, the penalty bit is set to the second value, allowing fast boot-up. When attacks are detected or suspected, the penalty bit is set to the first value, imposing the delayed start-up penalty. This dynamic adjustment optimizes both security and performance.

Inventive Principle:
Principle #15Dynamics

3Reliability

If the penalty bit is set to indicate delayed start-up by default, then security against reset attacks is improved, but normal operation without attacks still incurs unnecessary delay

Engineering Contradiction:
Improvesecurity against reset attacksVSAvoidboot-up speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies feedback by continuously monitoring for attacks and adjusting the penalty bit state accordingly. The system observes security conditions and provides feedback by setting or clearing the penalty bit based on whether attacks are detected. This feedback mechanism ensures that the delayed start-up penalty is applied only when necessary (when attacks are detected) and removed when the system is secure, optimizing both security and performance.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12579263B2Protective actions for a memory device based on detecting an attack
Publication Date: 2026.03.17 MICRON TECHNOLOGY INC
  • US12579263B2 patent drawing
  • US12579263B2 patent drawing
  • US12579263B2 patent drawing

AI summary

Methods, systems, and devices for protective actions for a memory device based on detecting an attack are described. In some systems, a memory device may detect whether a fault is injected into the memory device. The memory device may apply a delay during boot up if a fault is detected. To ensure the delay is applied, the memory device may default to applying the delay and may remove an indication to apply the delay if a fault is not detected. Additionally or alternatively, the memory device may erase information from non-volatile memory during boot up, for example, if a fault is detected. The memory device may be configured to ensure at least a specific portion of memory resources (e.g., resources configured to store sensitive information) is erased during boot up. In some examples, the memory device may store data using a stream cipher to improve security of the data.