RAM Security Module for Heuristic Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Connected objects, or IoT devices, lack effective security measures due to manufacturing cost constraints, making them vulnerable to unauthorized access and potential malfunctions.
Innovation Solution
A security module is introduced that integrates with existing RAM memory, utilizing a controller and data processing units to perform heuristic evaluations of the system's security state, and can trigger a shutdown or restart if vulnerabilities are detected, mimicking conventional DRAM behavior while enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security measures are implemented in connected objects, then security reliability is improved, but manufacturing cost increases
Solution Approach 1:
The patent merges security functionality with existing RAM memory by integrating a controller and data processing units directly into the memory module. This combination allows security evaluations to be performed using existing hardware resources without adding separate security devices, thereby improving security reliability while controlling manufacturing costs.
Solution Approach 2:
The RAM memory module is designed to perform both its conventional function of data storage and the additional function of security evaluation. The controller within the memory module can execute heuristic evaluations to detect unauthorized access patterns, making the memory component multi-functional and cost-effective for security purposes.
2Difficulty of detecting and measuring
If security evaluations are performed continuously, then detection capability is improved, but processing time increases
Solution Approach 1:
The system performs security evaluations periodically rather than continuously. The controller evaluates the security state at specific intervals or when triggered by particular events, such as memory access patterns that resemble unauthorized access. This periodic evaluation maintains detection capability while reducing overall processing time compared to continuous monitoring.
Solution Approach 2:
The security evaluation focuses on specific critical areas of memory rather than the entire memory space. The data processing units analyze particular memory regions for suspicious access patterns, which provides sufficient detection capability for security purposes while significantly reducing the processing time required compared to a comprehensive continuous scan of all memory.
3Reliability
If memory access control is implemented, then security state is improved, but device complexity increases
Solution Approach 1:
The memory access control functionality is merged into the existing RAM memory module by integrating a controller that manages access rights. This approach embeds security control within the memory component itself rather than adding a separate complex access control system, thereby improving security state while minimizing the increase in device complexity.
Solution Approach 2:
The memory module includes its own controller that autonomously manages access control based on predefined security rules. The data processing units within the memory can independently evaluate access requests and enforce security policies without requiring constant intervention from the main processor, which simplifies the overall system architecture while maintaining strong security control.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The invention relates to a module (MS) for securing a computer device (OC), the module comprising: - at least one RAM memory that can be accessed by a host processor (H-CPU) external to the securing module (MS), via a memory bus; - a controller (CTR) configured to be programmed by the host processor (H-CPU) via a control channel (CC); - data processing units (DPU) configured to be able to access zones of the memory via a DMA interface, the data processing units (DPU) being controlled by the controller (CTR); - the controller (CTR) being configured to control access to the memory either by the host processor (H-CPU) or by the data processing units (DPU); - the controller (CTR) being configured to evaluate heuristically a security status (st_secCTR) of the computer device (OC) as perceived by the controller (CTR), the heuristic evaluation comprising: (i) loading instructions into an instruction memory (MI) of the data processing unit (DPU) so that the latter carries out at least one operation on at least one portion of the memory; (ii) obtaining a result (reto, ret+) of the operation; (iii) determining the security status (st_secCTR) from the result - the controller (CTR) being configured to corrupt the memory depending on the security status (st_secCTR) in order to trigger a shutdown or restart of the operation of the host processor (H-CPU) of the computer device (OC).