Memory Integrity via Threefish Diffusers and Tweak Functions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory integrity solutions are vulnerable to corruption attacks and fail to efficiently detect or correct memory corruption, especially due to their deterministic nature and high computational resource requirements.

Innovation Solution

The proposed solution involves an apparatus with a memory controller that uses a block cipher like Threefish, diffusers, and inverse diffusers to encrypt and decrypt data, along with a tweak function and integrity check mechanisms to ensure memory integrity by generating and using integrity values and keys based on physical memory addresses, thereby providing a deterministic approach to memory integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption of memory is used to protect data, then data security is improved, but vulnerability to memory corruption attacks remains

Engineering Contradiction:
Improvedata securityVSAvoidmemory corruption attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary integrity checking mechanism between the encrypted memory and the processor. This intermediary system uses hash functions and checksums to verify data integrity, acting as a mediator that detects corruption without decrypting the data, thus maintaining security while preventing corruption attacks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary integrity verification actions by computing hash values and checksums before data is written to encrypted memory. This preliminary action creates a reference integrity signature that can be used to detect any subsequent corruption, allowing the system to identify and reject corrupted data before it reaches the processor

Inventive Principle:
Principle #10Preliminary action

2Quantity of substance

If parity checking is used for memory integrity, then storage cost is reduced, but determinism to adversary increases

Engineering Contradiction:
Improvestorage costVSAvoiddeterminism to adversary
Core Design Contradiction:
Quantity of substanceVSAdaptability or versatility

Solution Approach 1:

The patent changes the parameter of integrity verification from simple parity bits to more sophisticated hash functions and checksums. This parameter change maintains low storage overhead while introducing computational complexity that prevents adversaries from easily determining corruption patterns, as hash functions provide one-way verification without revealing data structure

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If large codes are used to verify data integrity, then adversary determinism is reduced, but storage cost increases

Engineering Contradiction:
Improveadversary determinismVSAvoidstorage cost
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The patent applies partial verification action by using selective integrity checking on critical data regions rather than applying full-coverage error correction codes to entire memory. This partial action reduces storage overhead while still providing sufficient protection against adversary attacks on the most vulnerable or critical data portions

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If integrity actions revert to previous state, then error correction is achieved, but computational resources are burdened

Engineering Contradiction:
Improveerror correctionVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the integrity verification function from the main computational path by implementing separate, dedicated integrity checking logic that operates independently from the primary data processing operations. This extraction allows integrity verification to occur with minimal impact on computational resources, as the checking mechanism is specialized and optimized for its specific function

Inventive Principle:
Principle #2Taking out (Extraction)

5Reliability

If integrity actions revert to previous state, then error correction is achieved, but data loss occurs

Engineering Contradiction:
Improveerror correctionVSAvoiddata loss
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent applies preliminary integrity verification before data is committed to storage or executed, allowing the system to detect and reject corrupted data before it causes problems. This preliminary action prevents the need to revert to previous states, as corrupted data is identified and discarded before it can impact system operation or cause data loss

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9990249B2Memory integrity with error detection and correction
Publication Date: 2018.06.05 INTEL CORP
  • US9990249B2 patent drawing
  • US9990249B2 patent drawing
  • US9990249B2 patent drawing

AI summary

Apparatus, systems, and/or methods may provide for identifying unencrypted data including a plurality of bits, wherein the unencrypted data may be encrypted and stored in memory. In addition, a determination may be made as to whether the unencrypted data includes a random distribution of the plurality of bits, for example based on a compressibility function. An integrity action may be implemented when the unencrypted data includes a random distribution of the plurality of bits, which may include error correction including a modification to ciphertext of the unencrypted data. Independently of error correction, a diffuser may generate intermediate and final ciphertext. In addition, a key and/or a tweak may be derived for a location in the memory. Moreover, an integrity value may be generated (e.g., as a copy) from a portion of the unencrypted data, and/or stored in a slot of an integrity check line based on the location.