Randomized Memory Access Control for SoC Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security methods for memory access in complex computer systems, such as set-top box SoCs, are vulnerable to unauthorized data access attempts, as they lack effective mechanisms to randomize and secure data access patterns, making it possible for attackers to circumvent security protocols by monitoring data access patterns.
Innovation Solution
A system and method for random data access in security applications, where a random number generator is used to select a process index and allocate time intervals for on-chip clients to access memory, ensuring that data access patterns are randomized and verified using digital signature algorithms, thereby preventing unauthorized access and emulating the burstiness of other clients' data access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional memory access schemes are used, then data access is simple and efficient, but security against unauthorized access is compromised
Solution Approach 1:
The patent implements dynamic memory access patterns by randomizing the order in which clients access memory and varying the timing of access requests. This dynamic behavior prevents unauthorized users from predicting or monitoring access patterns, thereby enhancing security without requiring fundamental changes to the memory access architecture
Solution Approach 2:
The system changes the parameters of memory access by introducing randomization in access timing and sequence. By varying these temporal parameters dynamically, the system maintains compatibility with existing memory interfaces while preventing pattern analysis attacks
2Reliability
If data access patterns are monitored for security checks, then security integrity is maintained, but unauthorized users can detect and circumvent security protocols
Solution Approach 1:
The patent introduces dummy or fake memory access requests that copy the characteristics of legitimate access patterns. These fabricated access patterns serve as decoys, making it difficult for unauthorized users to distinguish between real security monitoring traffic and dummy traffic, thereby protecting the actual security check patterns
3Productivity
If multiple clients access memory simultaneously, then system productivity is high, but data access patterns become predictable and vulnerable
Solution Approach 1:
The system dynamically randomizes the access patterns of multiple clients by varying the timing and sequence of their memory access requests. This dynamic randomization maintains high system throughput by allowing concurrent access while preventing predictable patterns that could be exploited by unauthorized users
Data Source
AI summary
Methods and systems for random data access for security applications are disclosed and may comprise generating on a chip, a random process index. A data process may be randomly selected on the chip utilizing the generated random process index. A time interval may be randomly allocated on the chip. After the time interval, the randomly selected data process may initiate processing of data. The processing of the data may comprise accessing the data and/or acquiring the data. The data may be verified by the selected data process prior to the processing of the data. The data may be verified utilizing a digital signature verification algorithm, for example.


