PUF-Based Memory Attestation for Trusted Boot Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure memory management systems in integrated devices face challenges in providing a trusted boot mechanism for small, simple devices without increasing complexity, particularly in ensuring platform integrity and cryptographic security.
Innovation Solution
The integration of a secure hardware element with hash function circuitry and a physically unclonable function (PUF) within the device, which directly interfaces with the random access memory (RAM) to obtain data, produce hash values, and cryptographically sign them, thereby ensuring memory integrity and authenticity without relying on the processor.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure hardware element with PUF and hash function circuitry is integrated directly with RAM, then cryptographic security and platform integrity are enhanced, but device complexity increases
Solution Approach 1:
The patent merges the secure hardware element (containing PUF and hash function circuitry) directly with the RAM device into a single integrated structure. This consolidation allows the secure element to directly access and authenticate memory contents without external processors, enhancing platform integrity while managing complexity through functional integration rather than separate components
Solution Approach 2:
The integrated secure hardware element performs multiple functions: it generates PUF values from physical characteristics, computes hash values of memory contents, and provides cryptographic authentication. This multi-functionality reduces the need for separate security modules, processors, and authentication hardware, thereby enhancing security capabilities without proportionally increasing overall device complexity
2Reliability
If a processor is used to access memory and perform cryptographic functions, then computational flexibility is maintained, but security and speed are reduced due to potential processor compromises
Solution Approach 1:
The patent segments the cryptographic security functions (PUF generation, hash computation, authentication) from the main processor by integrating them directly into the RAM device. This segmentation isolates critical security operations from potential processor compromises while maintaining system functionality, as the secure element operates independently to authenticate memory contents without requiring processor intervention
Solution Approach 2:
The integrated secure hardware element acts as an intermediary between the processor and RAM, performing cryptographic authentication of memory contents before processor access. This intermediary function ensures that even if the processor is compromised, it cannot access unauthorized or tampered memory contents, as the secure element independently validates memory integrity through PUF-based authentication
Data Source
Figure 1
Figure 2
Figure 3
AI summary
According to an example aspect of the present invention, there is provided an apparatus comprising a random access memory device, at least one processing core coupled via a first interface with the random access memory device, and a secure hardware element, comprising hash function circuitry, and coupled directly via a second interface with the random access memory device, the secure hardware element configured to obtain as input data from a memory space of the random access memory device, to produce as output a hash value of the input, and to cryptographically sign the hash value using a physically unclonable function value of the apparatus.