Memory Device Attack Detection via Dual Physical Address Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Memory devices face challenges in preventing data leakage and program code changes due to external attacks, such as fault attacks using lasers or X-rays, which compromise the security of sensitive data stored in security memory devices.
Innovation Solution
A memory device with enhanced security functions, including a processor, address generator, and attack detecting circuit, which generates and compares data across different physical addresses in nonvolatile memories to detect attacks and prevent data leakage by storing identical data in separate physical locations, thereby ensuring data integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If data is stored in a single physical location in nonvolatile memory, then storage efficiency is improved, but security against fault attacks deteriorates
Solution Approach 1:
The patent divides the storage system into multiple nonvolatile memory devices (first and second nonvolatile memories) and stores identical data in different physical locations across these devices. This segmentation allows the system to maintain storage efficiency while improving security, as fault attacks affecting one memory device can be detected by comparing data across multiple devices.
2Reliability
If multiple nonvolatile memories are used to store identical data for security, then security is improved, but device complexity increases
Solution Approach 1:
The patent combines multiple nonvolatile memory devices into a unified storage system managed by a single controller. The controller handles data writing to multiple devices and performs read operations by comparing data across devices, thereby improving security while managing the complexity through centralized control rather than requiring separate management systems for each memory device.
Solution Approach 2:
The patent implements a feedback mechanism where the controller reads data from multiple nonvolatile memory devices and compares the data to detect faults. When data inconsistency is detected, the system can identify potential attacks or errors and respond appropriately, providing continuous monitoring and verification that enhances security without requiring overly complex external systems.
3Reliability
If data is stored in separate physical locations for attack detection, then security is improved, but access time increases
Solution Approach 1:
The patent applies partial verification by comparing data only when specifically requested (e.g., during read operations or when security verification is needed) rather than continuously verifying all data in real-time. This approach maintains security through comparison while minimizing the impact on normal access operations, as the excessive action of full continuous verification is avoided.
Data Source
AI summary
A memory device includes an address generator which generates a first physical address and a second physical address different from the first physical address. A first nonvolatile memory includes the first physical address, and a second nonvolatile memory includes the second physical address. An attack detecting circuit detects whether the first and second nonvolatile memories are attacked. The attack detecting circuit receives first data from the first nonvolatile memory and receives second data from the second nonvolatile memory, compares the first data and the second data with each other, and determines whether the first and second nonvolatile memories are attacked on the basis of a comparison result of the first data and the second data.


