Memory Device Security Hardware for Bus Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer systems are vulnerable to 'man in the middle' or 'bus sniffing' attacks during authentication procedures due to the reliance on system buses for transmitting authentication data, which can lead to compromised security and performance issues.

Innovation Solution

Incorporating security hardware into nonvolatile memory devices that allows for internal measurement and verification of memory content, eliminating the need for bus-based authentication data transmission and enabling faster cryptographic operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated microprocessor is used to authenticate hardware devices and memory, then authentication capability is improved, but system vulnerability to bus attacks worsens

Engineering Contradiction:
Improveauthentication capabilityVSAvoidvulnerability to bus attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication functionality from the system bus environment and relocates it directly into the memory device. The memory device now performs self-authentication using embedded security hardware and cryptographic keys stored within its own secure elements, eliminating the need to transmit authentication data over the vulnerable system bus. This extraction of the authentication function from the bus environment resolves the contradiction by maintaining authentication capability while removing the attack vector.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary layer in the form of a trusted platform module (TPM) or secure element embedded within the memory device. This intermediary handles all cryptographic operations and authentication processes internally, acting as a secure mediator that never exposes authentication data to the system bus. The intermediary protects the authentication process while enabling verification of memory content genuineness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authentication data is transmitted over the system bus, then authentication process is enabled, but security against attacks worsens

Engineering Contradiction:
Improveauthentication processVSAvoidsecurity against attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The memory device performs self-authentication using internally embedded security hardware and cryptographic keys. The device measures its own memory content, computes cryptographic hashes, and verifies its authenticity without requiring external authentication data transmission. This self-service approach maintains the authentication process while completely eliminating the security vulnerability associated with bus-based data transmission.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Instead of having the system authenticate the memory device through bus communication, the patent inverts the approach by having the memory device authenticate itself internally. The authentication flow is reversed: rather than the processor querying the memory device, the memory device proactively measures and verifies its own content using embedded security hardware, then presents verification results to the processor.

Inventive Principle:
Principle #13The other way round (Inversion)

3Device complexity

If cryptographic functions are performed by software, then system complexity is reduced, but execution speed worsens

Engineering Contradiction:
Improvesystem complexityVSAvoidcryptographic operation speed
Core Design Contradiction:
Device complexityVSSpeed

Solution Approach 1:

The patent merges the cryptographic processing functionality directly into the memory device's hardware architecture. Security hardware including cryptographic engines, hash computation units, and key management circuits are integrated alongside the memory array and control logic. This merging eliminates the need for separate software-based cryptographic processing, achieving both hardware-level speed and a unified device architecture rather than increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent replaces software-based cryptographic operations with dedicated hardware circuits embedded in the memory device. Hardware implementation of cryptographic algorithms provides orders of magnitude faster execution compared to software implementations while being integrated into the memory device's control logic, thus not increasing system complexity but rather consolidating functions into a single unified device.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10296421B2Memory devices and systems with security capabilities
Publication Date: 2019.05.21 MICRON TECHNOLOGY INC
  • US10296421B2 patent drawing
  • US10296421B2 patent drawing
  • US10296421B2 patent drawing

AI summary

Several embodiments of systems incorporating memory devices are disclosed herein. In one embodiment, a memory device can include a controller, a main memory operably coupled to the controller, and security hardware operably coupled to the controller and to the main memory. The main memory can include a plurality of memory regions and at least one reserved memory region configured to store genuine backups of memory content stored in the plurality of memory regions. In operation, the security hardware is configured to measure memory content of the plurality of memory regions before startup, shutdown, and reset of the memory device; compare the measured value to an expected value; and direct the controller to replace the memory content with a genuine backup of the memory content stored in the at least one reserved memory region if the measured value and the expected value are not in accord.