Non-Volatile Memory Security via Poly Fuse and Floating Gate Combination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Non-volatile memory devices are becoming increasingly insecure against external attacks, as recent methods have been developed to retrieve data from EEPROM memory devices by probing floating gate potentials, compromising the security of stored data.

Innovation Solution

A non-volatile memory device is designed with a combination of poly fuse and floating gate memory blocks on a single die, requiring incompatible reverse-engineering techniques from both sides, and additional security measures such as bit line scrambling and distributed data storage across multiple memory blocks, making it difficult for hackers to access both simultaneously.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single type of non-volatile memory block is used, then the device structure is simple, but the security against external attacks is insufficient

Engineering Contradiction:
ImprovesecurityVSAvoidmemory structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The memory device is divided into multiple independent memory blocks (first non-volatile memory block and second non-volatile memory block) with different memory types. Each block stores a portion of the external data, and they require incompatible attack techniques to retrieve data, thereby segmenting the security defense across multiple structural units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines different memory types (e.g., poly fuse memory and floating gate memory) within the same device to create a composite memory structure. This composite approach leverages the security strengths of each memory type against different attack vectors, making the overall device more resistant to external attacks.

Inventive Principle:
Principle #40Composite materials

2Reliability

If data is stored in a single memory block, then the storage structure is simple, but the resistance against reverse-engineering is reduced

Engineering Contradiction:
Improveresistance against reverse-engineeringVSAvoiddata distribution structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

External data is divided into multiple portions and distributed across different memory blocks. The first portion is stored in the first non-volatile memory block and the second portion is stored in the second non-volatile memory block, creating a segmented data storage structure that requires multiple attack approaches to compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary distribution mechanism that splits data into multiple portions before storage. This intermediary step ensures that no single memory block contains the complete data, and the portions can only be reassembled by successfully accessing multiple blocks through incompatible attack techniques.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2074629B1A secure non-volatile memory device and a method of protecting data therein
Publication Date: 2012.10.24 NXP BV
  • EP2074629B1 patent drawingFigure 1
  • EP2074629B1 patent drawingFigure 2
  • EP2074629B1 patent drawingFigure 3

AI summary

The invention relates to a non- volatile memory device comprising: an input for providing external data (D1) to be stored on the non- volatile memory device; and a first non- volatile memory block (100) and a second non- volatile memory block (200), the first non-volatile memory block (100) and the second non-volatile memory block (200) being provided on a single die (10), wherein the first non- volatile memory block (100) and second non- volatile memory block (200) are of a different type such that the first non- volatile memory block (100) and the second non- volatile memory block (200) require incompatible external attack techniques in order to retrieve data there from, the external data (D1) being stored in a distributed way (D1 ', D1 ") into both the first non- volatile memory block (100) and the second non- volatile memory block (200). The invention further relates to method of protecting data in a non- volatile memory device.