Two-Stage OTP Memory Locking for Secure NVM Serialization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure storage solutions for non-volatile memory (NVM) often require all data to be known at the serialization stage, leading to costly delays and inventory management issues due to the need for a single-stage locking process, which is not feasible in situations where information is unknown or uncertain.
Innovation Solution
A two-stage process for locking non-volatile memory (NVM) using a one-time programmable (OTP) memory with write-lock and erase-lock bits, allowing for initial data writing and later selection and erasure of non-chosen options, ensuring the NVM becomes read-only after both locking stages are completed.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If a single-stage locking process is used for NVM, then security is simplified and implementation is easier, but it causes costly delays and inventory management issues when data is unknown or uncertain
Solution Approach 1:
The locking process is segmented into two distinct stages: a first locking stage that occurs during serialization when data is written to NVM, and a second locking stage that occurs later when final data selection is made. This segmentation allows the system to progress through manufacturing without requiring all decisions to be made at once, thereby reducing delays while maintaining security through progressive locking.
Solution Approach 2:
The first locking stage performs preliminary security establishment by locking the NVM against writes after initial data is written during serialization. This preliminary action secures the memory against modification while still allowing controlled erasure of non-final data in later stages, enabling time-to-market reduction without compromising ultimate security.
2Reliability
If all data is written and locked during serialization, then security is enhanced, but it requires all information to be known in advance which is not always feasible
Solution Approach 1:
The security locking is segmented into multiple stages with different permission levels. The first lock protects against writes, while a second lock protects against erasures. This allows the system to maintain security (reliability) at each stage while adapting to different data selection needs (versatility) as the process progresses.
Solution Approach 2:
The security model is made dynamic by allowing different operations (write vs. erase) to be permitted at different stages. Initially, writes are permitted but erasures are restricted; later, both are restricted. This dynamic approach provides flexibility in data selection while maintaining appropriate security constraints at each phase.
3Adaptability or versatility
If a two-stage locking process is implemented, then flexibility in data selection is improved, but the device complexity increases with additional OTP bits and control logic
Solution Approach 1:
The complexity of the two-stage locking control is extracted and offloaded to external processing systems. The OTP memory bits serve as simple flags that indicate the current locking stage, while the actual control logic and decision-making are performed externally, reducing the complexity burden on the hardware device itself.
Solution Approach 2:
The OTP memory structure is designed with universal applicability - the same basic OTP bits and locking mechanism can serve multiple purposes across different serialization scenarios. The two-stage process provides a universal framework that can accommodate various data selection needs without requiring custom hardware for each specific application.
4Reliability
If NVM is locked as read-only after programming, then security is maximized, but it prevents later erasure which is needed when data options need to be selected
Solution Approach 1:
The read-only protection is segmented into two distinct locking mechanisms: a first lock that prevents writes and a second lock that prevents erasures. By applying these locks sequentially at different stages, the system maximizes data protection (reliability) while maintaining ease of operation (erasure capability) during the intermediate phase when data selection is needed.
Solution Approach 2:
The first locking action is performed preliminarily to protect against writes, but it is designed to coexist with controlled erasure operations. This preliminary protection establishes a baseline security level while preserving the operational flexibility needed for later data selection and erasure before the final second lock is applied.
Data Source
AI summary
In one embodiment, an apparatus includes a non-volatile memory, a one-time programmable (OTP) memory, and a processor operative to write data values to the non-volatile memory and then initiate programming of a first bit of the OTP memory, the first bit being associated with locking the non-volatile memory from further data being written thereto, and after the non-volatile memory has been locked from further data being written thereto, initiate programming of the second bit of the OTP memory in order to lock the non-volatile memory from further data being erased therefrom.


