Protected Memory Module Authenticating Host Code
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional protection mechanisms for ensuring a trustworthy operating environment are complex and expensive, requiring hardware modifications to the host processor for secure boot processes.
Innovation Solution
A protected memory module with a memory controller that authenticates host-executable code, selectively allowing access based on authenticity, ensuring only trustworthy code is executed without modifying the host processor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hardware modifications are made to the host processor to implement secure boot processes, then the security and trustworthiness of the operating environment is improved, but the device complexity and manufacturing cost increase
Solution Approach 1:
A security module is introduced as an intermediary component between the host processor and the memory system. This security module contains a secure boot processor that independently verifies boot code authenticity, allowing the main host processor to remain unmodified while security functions are performed by the intermediary security module during the boot process.
Solution Approach 2:
The system is divided into separate functional components: the host processor for general computing tasks, the security module for security verification, and the memory controller for code storage and delivery. This segmentation allows security functionality to be isolated in a dedicated module rather than requiring modifications to the entire host processor architecture.
2Reliability
If hardware modifications are made to the host processor to implement secure boot processes, then the trustworthiness of code execution is improved, but the manufacturing cost increases
Solution Approach 1:
The security module serves as a cost-effective intermediary that provides secure boot functionality without requiring expensive modifications to the host processor. The security module can be implemented as a separate, standardized component that is manufactured independently and integrated into the system, reducing overall manufacturing complexity and cost.
Solution Approach 2:
Instead of modifying each host processor individually, the security functionality is copied into a separate security module that can be mass-produced and reused across multiple systems. This approach leverages economies of scale and avoids the high costs of customizing each processor unit.
3Reliability
If the host processor is adapted to perform host-based secure boot process, then the security verification capability is improved, but the ease of operation and system simplicity deteriorates
Solution Approach 1:
The security module acts as an intermediary that handles all security verification operations independently. The host processor simply boots and executes code without needing to understand or perform security checks, maintaining operational simplicity while security verification capability is enhanced by the dedicated security module.
Solution Approach 2:
The security module performs self-service by independently executing the secure boot process and verifying code authenticity without requiring the host processor to be adapted or involved in security operations. The host processor operates independently, focusing on its primary computing functions while the security module handles security verification autonomously.
Data Source
AI summary
Some demonstrative embodiments of the invention include a method, device and/or system of selectively allowing a host processor to access a host-executable code. A host apparatus may include, for example, a host processor; and a protected memory module comprising: a memory to maintain a host-executable code to be executed by the host processor; and a memory controller to authenticate the host-executable code, and to selectively allow the host processor to access the host-executable code based on an authenticity of the host-executable code. Other embodiments are described and claimed.


