Non-Volatile Memory Security Extensions via Data Scrambling
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Non-volatile memory (NVM) is vulnerable to side channel attacks and intrusive reverse engineering, making it insecure for storing secret keys and critical information, and relying on external secure elements increases costs and complexity.
Innovation Solution
Implementing address and data scrambling, along with differential data storage in the NVM controller to minimize exposure to side channel attacks and obfuscate stored data, eliminating the need for external secure elements by translating data into a form less prone to attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If NVM is used to store secret keys and critical information, then storage capacity and accessibility are improved, but security against side channel attacks and reverse engineering deteriorates
Solution Approach 1:
The NVM is divided into secure and non-secure regions. The secure region stores encrypted secret keys and critical information, while the non-secure region stores other data. This segmentation allows the system to maintain the storage capacity benefits of NVM while protecting sensitive data in the secure region through encryption and controlled access.
Solution Approach 2:
A secure element or trusted execution environment acts as an intermediary between the processor and the NVM. This intermediary handles encryption/decryption operations and controls access to the secure region, preventing direct access to plaintext secret keys while maintaining the accessibility benefits of NVM for authorized operations.
2Object-affected harmful factors
If external secure elements are used to protect secret keys, then security is improved, but bill of material cost, board space and system complexity increase
Solution Approach 1:
The patent combines the secure element functionality with the existing NVM controller and processor. The NVM controller is enhanced with encryption capabilities and secure region management, merging previously separate functions into a unified on-chip solution. This reduces the need for external secure elements while maintaining security protection.
Solution Approach 2:
The NVM controller is designed to perform multiple functions: standard NVM access, encryption/decryption operations, and secure region management. This multi-functionality eliminates the need for dedicated external secure elements, reducing system complexity and component count while providing comprehensive security protection.
3Speed
If data is stored in plaintext in NVM, then read/write speed is improved, but exposure to side channel attacks increases
Solution Approach 1:
Different security measures are applied to different regions of the NVM. The secure region uses encryption and controlled access to protect against side channel attacks, while the non-secure region maintains fast plaintext access. This local differentiation allows the system to optimize for speed where security is less critical while providing enhanced protection where needed.
Solution Approach 2:
The patent changes the state of data in the secure region from plaintext to encrypted form. This parameter change (encryption) increases protection against side channel attacks while the NVM controller maintains fast access speeds by handling encryption/decryption efficiently during read/write operations, minimizing performance impact.
Data Source
AI summary
The disclosed embodiments provide security extensions for memory (e.g., non-volatile memory) by means of address and data scrambling and differential data storage to minimize exposure to side channel attacks and obfuscate the stored data. The scrambling function maximizes reverse engineering costs when recovering sequences of secret keys.


