Nonvolatile Memory Data Security via Distributed Erase Flags
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing data in nonvolatile memory of Field-Programmable Gate Arrays (FPGAs) are inadequate, as they can be easily cracked by identifying and damaging security bits, leading to unauthorized data access and reduced security.
Innovation Solution
A data processing method that changes the default state of nonvolatile memory from unencrypted to encrypted by performing a full erase operation, storing data with a flag information, and prohibiting data readout if the flag information is unreadable, thereby increasing the difficulty of cracking and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security bits are set to encrypt data in nonvolatile memory, then data security is improved, but the device becomes readable when security bits are damaged or precisely erased, reducing security effectiveness
Solution Approach 1:
The patent divides the security mechanism into multiple security bits distributed across different memory banks. Instead of relying on a single centralized security bit, the security function is segmented into multiple independent bits located in different physical regions of the nonvolatile memory, making precise erasure attacks more difficult
Solution Approach 2:
The patent implements different security configurations in different local regions of the memory. Each memory bank can have its own security bit settings, allowing selective encryption of different data regions. This local differentiation prevents criminals from cracking all data by attacking a single security bit location
2Device complexity
If only one security bit or centralized security bits are used, then device complexity is reduced, but the device becomes vulnerable to precise positioning erasure attacks
Solution Approach 1:
The security bit configuration is segmented across multiple memory banks rather than using a single centralized security bit. Each bank contains its own security bit, creating a distributed security architecture that increases resistance to precise erasure attacks while maintaining manageable complexity
Solution Approach 2:
The patent adds a spatial dimension to security bit distribution by placing security bits in different memory banks across the memory array. This dimensional distribution transforms the security architecture from a single-point vulnerability to a multi-point distributed system, enhancing security without proportionally increasing complexity
3Ease of operation
If the default state of nonvolatile memory is unencrypted, then ease of operation is improved, but data security is compromised as criminals can read data directly
Solution Approach 1:
The patent applies preliminary anti-action by pre-configuring security bits to an encrypted state as the default configuration. This preliminary security measure is established before any data storage operation, automatically preventing unauthorized reading without requiring additional user actions or complex security protocols
Data Source
AI summary
The present disclosure provides a data processing method and a device for a nonvolatile memory and a storage medium. The data processing method comprises: performing a full erase operation on the nonvolatile memory if a full erase operation command is received, such that the nonvolatile memory enters an initial state, wherein the initial state refers to a state in which all operations performed on the nonvolatile memory are valid; in the initial state, storing a data if the data is written in the memory is detected, wherein the data comprises a flag information; detecting the flag information if a data readout command triggered by a user is received; and identifying that the nonvolatile memory is in a default state and prohibiting the user from reading the data stored in the nonvolatile memory if the flag information is detected as an unreadable flag information.


