Memory Controller Runtime Integrity Checking via Hardware Scrubbing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current memory integrity checking solutions are inefficient as they require memory access permissions for all memory regions, consume memory access bandwidth, and are not transparent to system software, making them ineffective in detecting and preventing malicious attacks and data corruption.

Innovation Solution

A memory controller with a hardware memory scrubber and RTIC engine that performs hash-based runtime integrity checks, integrated with ECC memory scrubbing, allowing for transparent security without additional memory bandwidth usage, and enabling detection of errors beyond ECC capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If memory integrity checking is performed using traditional solutions, then security against malicious attacks is improved, but memory access bandwidth consumption increases and system performance deteriorates

Engineering Contradiction:
Improvememory integrityVSAvoidmemory access bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent combines runtime integrity checking with the existing memory scrubbing function, merging two separate operations into one unified process. The integrity check is performed during the scrubbing operation, eliminating the need for separate integrity checking passes and reducing overall memory bandwidth consumption.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The memory scrubbing mechanism is enhanced to serve dual purposes: traditional error correction and new integrity checking. By making the scrubbing mechanism universal, the system achieves both error correction and integrity verification without requiring dedicated resources for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If memory integrity checking is performed using traditional solutions, then security against malicious attacks is improved, but device complexity increases due to additional hardware requirements

Engineering Contradiction:
Improvememory integrityVSAvoidhardware structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The integrity checking system utilizes the existing memory scrubbing hardware and control logic to perform integrity verification. The scrubbing mechanism serves itself by incorporating integrity checking into its existing operation flow, eliminating the need for separate dedicated integrity checking hardware.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

By designing the scrubbing mechanism to handle both error correction and integrity checking, the patent reduces hardware complexity. The same hardware infrastructure is used for multiple purposes, avoiding the need for additional specialized components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If memory scrubbing operates at high speed, then productivity is improved, but accuracy of integrity checking may be compromised

Engineering Contradiction:
Improvememory scrubbing speedVSAvoidintegrity check accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The integrity checking is performed continuously during the memory scrubbing operation without interruption. The checking process is embedded within the scrubbing flow, ensuring that integrity verification is maintained at all times while preserving the continuous high-speed operation of the scrubbing mechanism.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS11620184B2Runtime integrity checking for a memory system
Publication Date: 2023.04.04 NXP BV
  • US11620184B2 patent drawing
  • US11620184B2 patent drawing
  • US11620184B2 patent drawing

AI summary

Various embodiments relate to a memory controller, including: a memory interface connected to a memory; an address and command logic connected to the memory interface and a command interface, wherein the address and control logic is configured to receive a memory read request; a memory scrubber configured to cycle through memory locations and to read data from those locations; a region selector configured to determine when a memory location read by the memory scrubber is within an integrity checked memory region; a runtime integrity check (RTIC) engine connected to a read data path of the memory interface, wherein the RTIC engine is configured to calculate an integrity check value for the RTIC region using data read from the checked memory region by the memory scrubber; and a RTIC controller configured to compare the calculated integrity check value for the checked memory region to a reference integrity check value for the checked memory region.