Memory Device Security Hardware for Bus Attack Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer systems are vulnerable to 'man in the middle' or 'bus sniffing' attacks during authentication procedures due to the reliance on system buses for transmitting authentication data, which can lead to compromised security and performance issues.
Innovation Solution
Incorporating security hardware into nonvolatile memory devices that allows for internal measurement and verification of memory content, eliminating the need for bus-based authentication data transmission and enabling faster cryptographic operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dedicated microprocessor is used to authenticate hardware devices and memory, then authentication capability is improved, but system vulnerability to bus attacks worsens
Solution Approach 1:
The patent extracts the authentication functionality from the system bus environment and relocates it directly into the memory device. The memory device now performs self-authentication using embedded security hardware and cryptographic keys stored within its own secure elements, eliminating the need to transmit authentication data over the vulnerable system bus. This extraction of the authentication function from the bus environment resolves the contradiction by maintaining authentication capability while removing the attack vector.
Solution Approach 2:
The patent introduces an intermediary layer in the form of a trusted platform module (TPM) or secure element embedded within the memory device. This intermediary handles all cryptographic operations and authentication processes internally, acting as a secure mediator that never exposes authentication data to the system bus. The intermediary protects the authentication process while enabling verification of memory content genuineness.
2Ease of operation
If authentication data is transmitted over the system bus, then authentication process is enabled, but security against attacks worsens
Solution Approach 1:
The memory device performs self-authentication using internally embedded security hardware and cryptographic keys. The device measures its own memory content, computes cryptographic hashes, and verifies its authenticity without requiring external authentication data transmission. This self-service approach maintains the authentication process while completely eliminating the security vulnerability associated with bus-based data transmission.
Solution Approach 2:
Instead of having the system authenticate the memory device through bus communication, the patent inverts the approach by having the memory device authenticate itself internally. The authentication flow is reversed: rather than the processor querying the memory device, the memory device proactively measures and verifies its own content using embedded security hardware, then presents verification results to the processor.
3Device complexity
If cryptographic functions are performed by software, then system complexity is reduced, but execution speed worsens
Solution Approach 1:
The patent merges the cryptographic processing functionality directly into the memory device's hardware architecture. Security hardware including cryptographic engines, hash computation units, and key management circuits are integrated alongside the memory array and control logic. This merging eliminates the need for separate software-based cryptographic processing, achieving both hardware-level speed and a unified device architecture rather than increasing overall system complexity.
Solution Approach 2:
The patent replaces software-based cryptographic operations with dedicated hardware circuits embedded in the memory device. Hardware implementation of cryptographic algorithms provides orders of magnitude faster execution compared to software implementations while being integrated into the memory device's control logic, thus not increasing system complexity but rather consolidating functions into a single unified device.
Data Source
AI summary
Several embodiments of systems incorporating memory devices are disclosed herein. In one embodiment, a memory device can include a controller, a main memory operably coupled to the controller, and security hardware operably coupled to the controller and to the main memory. The main memory can include a plurality of memory regions and at least one reserved memory region configured to store genuine backups of memory content stored in the plurality of memory regions. In operation, the security hardware is configured to measure memory content of the plurality of memory regions before startup, shutdown, and reset of the memory device; compare the measured value to an expected value; and direct the controller to replace the memory content with a genuine backup of the memory content stored in the at least one reserved memory region if the measured value and the expected value are not in accord.


