Non-Volatile Memory Security via Dual-Block Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Non-volatile memory devices are vulnerable to external attacks, as recent methods have been developed to retrieve data from EEPROM memory devices by probing floating gate potentials, compromising data security.

Innovation Solution

A non-volatile memory device with two different types of memory blocks on a single die, requiring incompatible external attack techniques, combined with an encryption circuit using unique data as an encryption key, making it difficult to retrieve data without accessing both blocks simultaneously, and additional security measures such as interlacing and bit-line scrambling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single type of non-volatile memory block is used, then the device structure is simple, but the data security is vulnerable to external attacks

Engineering Contradiction:
Improvedata securityVSAvoidmemory block structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The memory device is divided into multiple memory blocks (first non-volatile memory block and second non-volatile memory block) of different types. Each block requires different attack techniques to be compromised, so that attacking one block does not reveal information about the other block or the encryption key stored in the first block.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption key is stored in memory block, then encryption functionality is achieved, but the memory block becomes vulnerable to attack

Engineering Contradiction:
Improveencryption securityVSAvoidvulnerability to external attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The first non-volatile memory block stores the encryption key, while the second non-volatile memory block stores the encrypted data. This separation creates an intermediary structure where the key and data are stored in different locations requiring different attack techniques, making it difficult for attackers to compromise both simultaneously.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If multiple memory blocks of different types are used, then resistance to external attacks is improved, but the device complexity increases

Engineering Contradiction:
Improveresistance to external attacksVSAvoidmemory block configuration
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

Different regions of the memory device have different properties - the first non-volatile memory block and second non-volatile memory block are of different types with different attack characteristics. This local differentiation ensures that each block provides specific security functions that complement each other, making comprehensive attack difficult.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9165663B2Secure non-volatile memory device and method of protecting data therein
Publication Date: 2015.10.20 NXP BV
  • US9165663B2 patent drawing
  • US9165663B2 patent drawing
  • US9165663B2 patent drawing

AI summary

The invention relates to a non-volatile memory device comprising: an input for providing external data to be stored on the non-volatile memory device; a first non-volatile memory block and a second non-volatile memory block, the first non-volatile memory block and the second non-volatile memory block being provided on a single die, wherein the first non-volatile memory block and second non-volatile memory block are of a different type such that the first non-volatile memory block and the second non-volatile memory block require incompatible external attack techniques in order to retrieve data there from; and—an encryption circuit for encrypting the external data forming encrypted data using unique data from at least the first non-volatile memory block as an encryption key, the encrypted data at least being stored into the second non-volatile memory block. The invention further relates to method of protecting data in a non-volatile memory device.