Memory Integrity Verification via Independent Logic Module
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing conditional access module (CAM) systems are vulnerable to unauthorized access through external attacks on the microprocessor and input/output module, which can compromise the security of encrypted media programs.
Innovation Solution
A system and method that involves a non-volatile reprogrammable memory communicatively coupled to a microprocessor, with a logical module performing a memory integrity check independently of the microprocessor, hiding the memory read operation from external access and ensuring that the memory integrity check is not accessible via the system input/output module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the microprocessor reads the memory contents to generate a checksum for verification, then the memory integrity can be checked, but the attacker may gain access to the memory through external attacks via the microprocessor and I/O module
Solution Approach 1:
A dedicated verification logic block is introduced as an intermediary component that directly accesses the memory through a separate verification bus, independent from the microprocessor's data bus. This intermediary structure enables memory integrity checking without exposing the memory to external attacks through the microprocessor interface.
Solution Approach 2:
The memory access path is segmented into two independent channels: a data bus for normal microprocessor operations and a separate verification bus for integrity checking. This segmentation isolates the verification function from the attack vector, allowing secure memory validation without compromising the main system to external threats.
2Ease of operation
If the memory read operation is performed through the microprocessor via the I/O module, then the system can access memory contents, but the attack surface is increased allowing external attacks
Solution Approach 1:
The verification system adds a new dimensional access path to the memory subsystem by introducing a dedicated verification bus that operates independently from the existing microprocessor data bus. This additional dimension enables memory access for verification purposes without increasing the attack surface of the original interface.
3Object-affected harmful factors
If a separate verification path is introduced to protect against attacks, then security is improved, but the device complexity increases
Solution Approach 1:
The verification function is extracted from the microprocessor's general-purpose interface and implemented as a dedicated separate path with its own logic block and bus. This extraction isolates the security-critical verification operation from the complex, attack-prone microprocessor interface, reducing the overall attack surface despite adding a separate path.
Data Source
AI summary
A system and method of verifying a content of a non-volatile reprogrammable memory communicatively coupled to a microprocessor is disclosed. The method comprises the steps of reading at least some of the data stored in the non-volatile reprogrammable memory, computing a value related to contents of the non-volatile reprogrammable memory, and comparing the value with a stored integrity value. The apparatus comprises a microprocessor, a non-volatile reprogrammable memory communicatively coupled to the microprocessor via a first communication path, the non-volatile memory for storing microprocessor program instructions, and a logical module, communicatively coupled to the non-volatile memory via a communication path independent from the first communication path, the logical module for verifying the data stored in the non-volatile reprogrammable memory by comparison of the contents of the non-volatile reprogrammable memory with a stored integrity value.


