Memory Controller Zeroization for Data Remanence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data protection methods are inadequate for preventing data remanence in semiconductor memories, particularly in high-performance computing platforms, as they require constant data flipping, are impractical for large data sets, and are vulnerable to malicious software and hardware interventions, and are limited by the speed of processors used in normal operational modes.
Innovation Solution
A hardware-based system that includes a tamper detector, zeroization generator, and selector to autonomously generate and apply zeroization data to memory, providing higher assurance data zeroization techniques that deter data recovery from semiconductor RAM devices, even when primary power is removed, without requiring new semiconductor technologies.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If constant data flipping is performed to prevent data remanence, then data security is improved, but system complexity and processing overhead increase significantly
Solution Approach 1:
The patent extracts the data flipping operation from the main processor and implements it through a dedicated memory controller that autonomously performs remanence prevention. This separates the security-critical function from general-purpose processing, reducing system complexity while maintaining security.
Solution Approach 2:
The patent implements preliminary zeroization actions that are triggered by tamper detection signals before actual tampering occurs. The memory controller proactively clears sensitive data when tamper indicators are detected, preventing data exposure without requiring complex real-time analysis.
2Reliability
If data flipping is performed frequently to prevent remanence, then data security is improved, but processing speed decreases due to operational overhead
Solution Approach 1:
The patent implements periodic data flipping through the memory controller at strategically determined intervals rather than continuously. The controller monitors memory access patterns and performs zeroization operations periodically when security conditions warrant it, maintaining security while minimizing interference with normal processing speed.
Solution Approach 2:
The memory controller autonomously manages data flipping operations without requiring processor intervention. It self-determines when zeroization is needed based on tamper indicators and memory state, eliminating the processing overhead that would result from processor-managed data flipping.
3Ease of manufacture
If processor-based data protection methods are used, then implementation is simple, but speed is limited by processor operational mode
Solution Approach 1:
The patent introduces a memory controller as an intermediary between the processor and memory subsystem. This intermediary handles security-critical operations at memory speed rather than processor speed, achieving high-speed operation while keeping the processor free for general-purpose tasks. The controller acts as a specialized co-processor for memory security functions.
4Reliability
If encryption is applied to protect data in memory, then data security is improved, but vulnerability to key recovery attacks increases
Solution Approach 1:
The patent implements preliminary zeroization actions triggered by tamper detection that occur before an attacker can recover cryptographic keys. When tamper indicators are detected, the memory controller immediately clears sensitive data from memory, preventing key extraction even if physical access is obtained. This proactive measure neutralizes the vulnerability to key recovery attacks.
Solution Approach 2:
The system prepares anti-tamper responses in advance by monitoring for tamper indicators and having zeroization routines ready to execute. This cushioning approach ensures that even if encryption is compromised, the sensitive data is already cleared before an attack can succeed, providing a safety buffer against key recovery vulnerabilities.
Data Source
AI summary
A method and apparatus for preventing compromise of data stored in a memory by assuring the deletion of data and minimizing data remanence affects is disclosed. The method comprises the steps of monitoring the memory to detect tampering, and if tampering is detected, generating second signals having second data differing from the first data autonomously from the first processor; providing the generated second signals to the input of the memory; and storing the second data in the memory. Several embodiments are disclosed, including self-powered embodiments and those which use separate, dedicated processors to generate, apply, and verify the zeroization data.


