Memory Command Origin Recognition for Trusted Shared Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory systems face challenges in securely managing access to shared memory resources among different domains, particularly in environments with trusted and non-trusted entities, leading to potential data breaches and integrity issues.
Innovation Solution
Implementing cyclic redundancy check (CRC) and Keccak message authentication code (KMAC) circuitry in memory devices to ensure data integrity, combined with a cache memory system that uses keyID and TEE bits to determine the origin of commands, optimizing for Computer Express Link (CXL) interfaces to manage access permissions based on trust domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional memory access control is used without domain identification, then access speed is maintained, but security and data integrity are compromised due to unauthorized access from non-trusted domains
Solution Approach 1:
The patent applies preliminary action by checking the TEE bit and keyID in the command stage before actual memory access occurs. This early verification of trusted domain status prevents unauthorized access attempts from reaching the memory resource, ensuring data integrity while maintaining efficient access control through pre-validation of command authenticity
Solution Approach 2:
The patent introduces an intermediary mechanism using the TEE bit and keyID as mediators between the command source and memory access. These intermediaries carry trust domain information that enables the memory device to verify command authenticity without requiring complex authentication protocols, resolving the contradiction between security and complexity
2Reliability
If hashing algorithms are used for data integrity verification, then data security is improved, but processing time and computational overhead increase
Solution Approach 1:
The patent extracts the essential security verification function from complex hashing algorithms and implements it through simpler CRC circuitry combined with TEE bit and keyID checking. This extraction maintains data security by verifying command authenticity and detecting tampering while avoiding the significant computational overhead of full hashing algorithms, thus reducing processing time
Solution Approach 2:
The patent uses computationally inexpensive CRC calculations instead of expensive hashing algorithms. The CRC check provides sufficient security for memory integrity verification without the heavy computational cost of hashing, effectively using a cheaper, faster alternative that meets the security requirements without the time penalty
3Productivity
If shared memory resources are accessible by multiple domains, then resource utilization efficiency is improved, but security risks increase due to potential unauthorized access
Solution Approach 1:
The patent applies local quality by associating specific memory regions with specific trusted domains through keyID mapping. Each memory region has localized security attributes defined by its associated keyID, allowing different security policies for different memory regions. This enables shared memory resources to be efficiently utilized by multiple domains while maintaining security through localized access control rules that prevent unauthorized access to specific regions
Data Source
AI summary
Systems, apparatuses, and methods related to data identity recognition for semiconductor devices are described. A system includes a host and a memory device coupled to the host via an interconnect bus. The host includes a host security manager configured to encrypt data of a command, perform a memory integrity check, allow access to memory of a memory device corresponding to an address of a command based on which entity associated with the host sent the command, generate security keys, program security keys into the memory device, program encryption ranges, or any combination thereof. The memory device includes a memory encryption manager and a memory device security manager. The memory device security manager is configured to detect whether a command was sent from a trusted domain of the host or non-trusted domain of the host and identify which entity associated with the host initiated the command.


