Persistent Main Memory Security via Nonvolatile Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Memory devices face challenges in securely authenticating and protecting sensitive information from unauthorized access and modification, particularly due to the time-consuming nature of cryptographic measurements and the risk of data loss during power disruptions.
Innovation Solution
Implementing persistent main memory that includes nonvolatile memory, such as phase change memory (PCM) or flash memory, which allows for secure hash algorithm (SHA) measurements and cryptographic key storage within the memory device, enabling efficient authentication of write commands and maintaining security information even during power loss, thus reducing the need for repeated security checks and re-loading of data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic measurements are performed to authenticate memory contents, then security protection is improved, but processing time and operational demands increase
Solution Approach 1:
The patent performs cryptographic measurements and authentication of memory contents during the boot process before the operating system and applications are loaded. By completing security verification in advance, the system ensures memory integrity without requiring repeated authentication during normal operation, thus resolving the contradiction between security protection and processing time.
2Speed
If volatile memory is used for main memory, then speed and operational demands are reduced, but data loss occurs during power disruptions
Solution Approach 1:
The patent divides main memory into volatile and non-volatile portions, with the non-volatile portion storing security-critical information such as cryptographic keys and authentication data. This segmentation allows the system to maintain fast access speeds for general memory operations while preserving critical security information across power cycles, preventing data loss without compromising overall system performance.
3Reliability
If repeated authentication checks are performed after power loss, then security is maintained, but productivity and operational efficiency decrease
Solution Approach 1:
The system performs authentication of memory contents and stores verification results in non-volatile memory during the boot process. After power loss, the system can quickly retrieve and verify previously stored authentication data without performing complete repeated authentication checks, thereby maintaining security while improving operational efficiency and productivity.
4Reliability
If cryptographic keys are stored externally to memory, then security is improved, but device complexity and access requirements increase
Solution Approach 1:
The patent integrates cryptographic key storage and authentication functionality directly within the non-volatile memory portion of main memory. By merging these security functions into the memory device itself, the system maintains strong security protection while reducing overall system complexity and eliminating the need for separate external key management hardware or software components.
Data Source
AI summary
Subject matter disclosed herein relates to memory devices and security of same.


