Non-Volatile Memory Power Cycle Counting for Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The vulnerability of IoT devices to physical security threats, where attackers can extract and read the memory from these devices, compromising sensitive information stored in them.

Innovation Solution

A method that increments a memory power cycle count upon each power-up of the memory device and compares it with a host power cycle count. If the counts do not match, a security reaction is applied to prevent data readout, such as marking the memory as corrupted or encrypting the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If removable memory is used in IoT devices, then ease of manufacture and replaceability are improved, but physical security vulnerability increases

Engineering Contradiction:
Improveease of manufactureVSAvoidphysical security vulnerability
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by establishing a power cycle count comparison mechanism before data extraction can occur. The memory device continuously monitors and compares its power cycle count with the host device's power cycle count, and preemptively applies security reactions (such as blocking read operations or encrypting data) when mismatches are detected, preventing unauthorized data access before attackers can extract useful information.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If memory security protection is implemented, then data protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the memory device to autonomously monitor its own power cycle count, compare it with the host device's count, and independently trigger security reactions without requiring external intervention. The memory controller automatically detects mismatches and applies protective measures such as blocking read operations or encrypting data, eliminating the need for complex external security systems while maintaining strong data protection.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250053692A1Protecting data stored by a non-volatile memory
Publication Date: 2025.02.13 KYNDRYL INC
  • US20250053692A1 patent drawing

AI summary

One or more embodiments relate to protecting data stored by a non-volatile memory of a memory device installed in a computing device. A technique includes in response to a power-up of the memory device, incrementing a memory power cycle count, and receiving a host power cycle count indicating a number of power-ups of the computing device. The technique includes, if the memory power cycle count is not equal to the host power cycle count, applying a security reaction to the memory, the security reaction being adapted for preventing a readout of the data.