Protected Memory Module Authenticating Host Code

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional protection mechanisms for ensuring a trustworthy operating environment are complex and expensive, requiring hardware modifications to the host processor for secure boot processes.

Innovation Solution

A protected memory module with a memory controller that authenticates host-executable code, selectively allowing access based on authenticity, ensuring only trustworthy code is executed without modifying the host processor.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware modifications are made to the host processor to implement secure boot processes, then the security and trustworthiness of the operating environment is improved, but the device complexity and manufacturing cost increase

Engineering Contradiction:
Improvesecurity of operating environmentVSAvoidhost processor complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security module is introduced as an intermediary component between the host processor and the memory system. This security module contains a secure boot processor that independently verifies boot code authenticity, allowing the main host processor to remain unmodified while security functions are performed by the intermediary security module during the boot process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system is divided into separate functional components: the host processor for general computing tasks, the security module for security verification, and the memory controller for code storage and delivery. This segmentation allows security functionality to be isolated in a dedicated module rather than requiring modifications to the entire host processor architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If hardware modifications are made to the host processor to implement secure boot processes, then the trustworthiness of code execution is improved, but the manufacturing cost increases

Engineering Contradiction:
Improvetrustworthiness of code executionVSAvoidmanufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security module serves as a cost-effective intermediary that provides secure boot functionality without requiring expensive modifications to the host processor. The security module can be implemented as a separate, standardized component that is manufactured independently and integrated into the system, reducing overall manufacturing complexity and cost.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of modifying each host processor individually, the security functionality is copied into a separate security module that can be mass-produced and reused across multiple systems. This approach leverages economies of scale and avoids the high costs of customizing each processor unit.

Inventive Principle:
Principle #26Copying

3Reliability

If the host processor is adapted to perform host-based secure boot process, then the security verification capability is improved, but the ease of operation and system simplicity deteriorates

Engineering Contradiction:
Improvesecurity verification capabilityVSAvoidsystem simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security module acts as an intermediary that handles all security verification operations independently. The host processor simply boots and executes code without needing to understand or perform security checks, maintaining operational simplicity while security verification capability is enhanced by the dedicated security module.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security module performs self-service by independently executing the secure boot process and verifying code authenticity without requiring the host processor to be adapted or involved in security operations. The host processor operates independently, focusing on its primary computing functions while the security module handles security verification autonomously.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7467304B2System, device, and method of selectively allowing a host processor to access host-executable code
Publication Date: 2008.12.16 ARM LTD
  • US7467304B2 patent drawing
  • US7467304B2 patent drawing
  • US7467304B2 patent drawing

AI summary

Some demonstrative embodiments of the invention include a method, device and/or system of selectively allowing a host processor to access a host-executable code. A host apparatus may include, for example, a host processor; and a protected memory module comprising: a memory to maintain a host-executable code to be executed by the host processor; and a memory controller to authenticate the host-executable code, and to selectively allow the host processor to access the host-executable code based on an authenticity of the host-executable code. Other embodiments are described and claimed.