Memory Initialization Bits Block Uninitialized Read Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing devices face challenges in securely preventing unauthorized access to confidential data across different phases of program execution, as conventional methods like clearing memory or power cycling are either inefficient or vulnerable to data leakage and remanence attacks.
Innovation Solution
The implementation of a hardware-based solution that automatically locks memories upon shutdown or sleep mode, using initialization bits to block read operations from uninitialized memory locations, ensuring data security without software configurations or CPU monitoring, and allowing read access only when data has been written in the current phase.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If confidential data is cleared before shutdown or sleep mode, then data security is improved, but latency and energy consumption increase
Solution Approach 1:
The patent applies preliminary action by setting initialization bits to a first value (indicating uninitialized state) before the program enters sleep mode or shutdown. This pre-positioning of security markers eliminates the need for time-consuming data clearing operations after shutdown, as the security state is established in advance. The initialization bits are set during the transition to sleep mode rather than during wake-up, thereby reducing latency.
Solution Approach 2:
The patent extracts the security verification function from the main data storage operation by using separate initialization bits that are dedicated solely to tracking the initialized state of memory locations. This separation allows the security mechanism to operate independently without interfering with normal data operations, reducing the time penalty associated with security checks.
2Reliability
If confidential data is cleared before shutdown or sleep mode, then data security is improved, but energy consumption increases
Solution Approach 1:
The patent applies preliminary action by setting initialization bits to a first value (indicating uninitialized state) before the program enters sleep mode or shutdown. This pre-positioning of security markers eliminates the need for energy-intensive data clearing operations after shutdown, as the security state is established in advance. The initialization bits are set during the transition to sleep mode rather than during wake-up, thereby reducing energy consumption.
Solution Approach 2:
The patent uses inexpensive initialization bits that can be rapidly set and reset without significant energy cost. These bits serve as disposable security markers that are set to indicate uninitialized state, provide security during sleep mode, and are then reset without substantial energy expenditure. The low-cost nature of these initialization bits makes them ideal for frequent security state transitions.
3Reliability
If a programmer clears every word of confidential data in memory, then data security is improved, but device complexity and error susceptibility increase
Solution Approach 1:
The patent applies self-service by automatically managing the security state of memory locations through initialization bits that are set and reset by the system itself rather than requiring manual programmer intervention. The hardware automatically tracks which memory locations have been initialized and enforces security policies based on these bits, freeing the programmer from the complex and error-prone task of manually clearing every word of confidential data.
Solution Approach 2:
The patent uses feedback mechanisms where the initialization bits provide continuous information about the security state of memory locations. The read driver circuitry monitors these initialization bits and automatically prevents access to uninitialized memory locations, creating a closed-loop security system that requires no programmer intervention and reduces complexity.
4Reliability
If power cycling is used to clear memory, then data security is improved, but it fails for non-volatile memories and is vulnerable to remanence attacks
Solution Approach 1:
The patent segments the security mechanism from the physical memory clearing operation by using separate initialization bits that logically track the security state without requiring physical erasure of memory contents. This segmentation allows the same security mechanism to work across different memory types (volatile and non-volatile) without relying on power cycling, which is ineffective for non-volatile memories. The security is enforced at the logical level rather than through physical memory destruction.
Data Source
AI summary
According to one implementation of the present disclosure, a memory array to block read-access of uninitialized memory locations is disclosed. The memory array includes: a plurality of memory cells apportioned into a plurality of memory columns and a plurality of memory rows, where each of the memory cells is configured to store a single bit of memory data; and one or more initialization columns corresponding to at least one of the plurality of memory columns. The initialization state of a memory row of the memory cells may be configured to be stored in: the memory row; a latch of word-line driver circuitry coupled to the memory array; or a memory cell of the one or more initialization columns of a corresponding row of the plurality of memory rows of the memory array.


