Memory Erase Circuitry for Cold Boot Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Memory devices retain data even after power is removed, allowing hackers to access sensitive information through cold boot attacks, as existing methods for overwriting data incur performance penalties and are vulnerable to software protection circumvention.
Innovation Solution
A memory device with erase circuitry that performs a forced write operation independently of the clock signal, using erase signal generation circuitry with capacitor circuitry to assert an erase signal if the control signal is not a pulse signal with a predetermined minimum frequency, ensuring secure and efficient data erasure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is overwritten immediately after use to prevent data remanence, then security against cold boot attacks is improved, but processing performance deteriorates due to the overhead of additional write operations
Solution Approach 1:
The system performs preliminary actions by setting up protection mechanisms in advance. The erase circuitry is pre-configured to automatically overwrite data when specific conditions are met (power loss detection, temperature changes), so that security protection is already in place before an attack can occur, eliminating the need for performance-costly immediate overwriting after each data operation.
Solution Approach 2:
The memory device serves itself by incorporating automatic data erasure functionality within the memory array. The erase circuitry autonomously detects security threats (such as unexpected power loss or temperature changes indicative of cold boot attacks) and performs data overwriting without requiring external processing device intervention, thus maintaining security while avoiding performance penalties.
2Ease of operation
If software protection measures are used to protect sensitive data, then ease of operation is improved, but reliability deteriorates as hackers can circumvent these measures through cold boot attacks
Solution Approach 1:
The patent introduces an intermediary hardware layer (erase circuitry with temperature sensing and power loss detection) between the software protection layer and the physical memory cells. This intermediary automatically executes data erasure based on physical conditions, creating a hardware-enforced security barrier that hackers cannot circumvent through software-based cold boot attacks, while maintaining ease of operation through automatic execution.
Solution Approach 2:
The patent replaces software-based protection mechanisms with hardware-based automatic erasure circuitry. The erase circuitry uses physical sensors (temperature sensors, power loss detection) and hardware logic to automatically overwrite data, substituting the mechanical/software approach with a hardware-enforced mechanism that is inherently more resistant to cold boot attacks while maintaining ease of operation.
3Reliability
If forced write operations are performed independently of the clock signal to ensure security, then reliability is improved, but device complexity increases due to additional circuitry requirements
Solution Approach 1:
The patent merges the erase circuitry with the existing memory array structure, integrating temperature sensors, power loss detection logic, and data overwriting functionality directly into the memory device fabric. This consolidation achieves clock-independent secure erasure while minimizing device complexity by reusing existing memory cell structures and control logic rather than adding completely separate hardware systems.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
Prevents data remanence and hacking by securely overwriting data in a clock-independent manner, enhancing security and efficiency in memory device operations.
Implementation Method 1
said erase signal generation circuitry comprises capacitor circuitry, and output circuitry configured to generate the erase signal in dependence on an output from the capacitor circuitry; the capacitor circuitry being configured to switch between a charging operation and a discharging operation dependent on the control signal
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
The present invention provides an apparatus and method for erasing data in a memory device comprising an array of memory cells, and configured to operate from a clock signal. The apparatus includes erase circuitry, responsive to receipt of an erase signal in an asserted state, to perform a forced write operation independently of the clock signal in respect of each memory cell within a predetermined erase region of said array. Further, erase signal generation circuitry is configured to receive a control signal and to maintain said erase signal in a deasserted state provided that the control signal takes the form of a pulse signal having at least a predetermined minimum frequency between pulses. The erase signal generation circuitry is further configured to issue said erase signal in said asserted state if the control signal does not take the form of said pulse signal. Such an approach enables the security of a memory device to be improved, and in particular prevents hackers from taking advantage of data remanence effects, by ensuring that stored data is overwritten in an efficient, and clock independent, manner, triggered by assertion of an erase signal generated if a pulse-based control signal does not take it is expected form.