Memory Integrity Verification via Independent Logic Module

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing conditional access module (CAM) systems are vulnerable to unauthorized access through external attacks on the microprocessor and input/output module, which can compromise the security of encrypted media programs.

Innovation Solution

A system and method that involves a non-volatile reprogrammable memory communicatively coupled to a microprocessor, with a logical module performing a memory integrity check independently of the microprocessor, hiding the memory read operation from external access and ensuring that the memory integrity check is not accessible via the system input/output module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the microprocessor reads the memory contents to generate a checksum for verification, then the memory integrity can be checked, but the attacker may gain access to the memory through external attacks via the microprocessor and I/O module

Engineering Contradiction:
Improvememory integrity verificationVSAvoidexternal attacks on memory
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A dedicated verification logic block is introduced as an intermediary component that directly accesses the memory through a separate verification bus, independent from the microprocessor's data bus. This intermediary structure enables memory integrity checking without exposing the memory to external attacks through the microprocessor interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The memory access path is segmented into two independent channels: a data bus for normal microprocessor operations and a separate verification bus for integrity checking. This segmentation isolates the verification function from the attack vector, allowing secure memory validation without compromising the main system to external threats.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If the memory read operation is performed through the microprocessor via the I/O module, then the system can access memory contents, but the attack surface is increased allowing external attacks

Engineering Contradiction:
Improvememory accessVSAvoidattack surface
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The verification system adds a new dimensional access path to the memory subsystem by introducing a dedicated verification bus that operates independently from the existing microprocessor data bus. This additional dimension enables memory access for verification purposes without increasing the attack surface of the original interface.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Object-affected harmful factors

If a separate verification path is introduced to protect against attacks, then security is improved, but the device complexity increases

Engineering Contradiction:
Improveexternal attacksVSAvoidcommunication paths
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The verification function is extracted from the microprocessor's general-purpose interface and implemented as a dedicated separate path with its own logic block and bus. This extraction isolates the security-critical verification operation from the complex, attack-prone microprocessor interface, reducing the overall attack surface despite adding a separate path.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8122215B1Method and apparatus for verifying memory contents
Publication Date: 2012.02.21 DIRECTV LLC
  • US8122215B1 patent drawing
  • US8122215B1 patent drawing
  • US8122215B1 patent drawing

AI summary

A system and method of verifying a content of a non-volatile reprogrammable memory communicatively coupled to a microprocessor is disclosed. The method comprises the steps of reading at least some of the data stored in the non-volatile reprogrammable memory, computing a value related to contents of the non-volatile reprogrammable memory, and comparing the value with a stored integrity value. The apparatus comprises a microprocessor, a non-volatile reprogrammable memory communicatively coupled to the microprocessor via a first communication path, the non-volatile memory for storing microprocessor program instructions, and a logical module, communicatively coupled to the non-volatile memory via a communication path independent from the first communication path, the logical module for verifying the data stored in the non-volatile reprogrammable memory by comparison of the contents of the non-volatile reprogrammable memory with a stored integrity value.