Secure Microcontroller RRAM Mapping for Low-Overhead Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing resistive-switching memory technologies lack efficient methods for secure data storage and access control, particularly in secure microcontrollers, leading to vulnerabilities in data integrity and unauthorized access.
Innovation Solution
A secure microcontroller with a two-terminal non-volatile memory array that operates in different modes, such as one-time programmable (OTP), rewritable (MTP), and physical unclonable function (PUF), and includes an access control module to validate data access requests based on predefined characterizations, reducing memory overhead through link tables and configuration data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If a unified resistive memory array is used for multiple storage modes (OTP, MTP, PUF), then memory density and integration are improved, but access control complexity and security management difficulty increase
Solution Approach 1:
The unified memory array is segmented into different operational modes (OTP, MTP, PUF) through the access control module that characterizes and validates requests based on data type. The link table structure also segments the access control logic into predefined characterizations and specific data mappings, resolving the complexity through structured division.
Solution Approach 2:
The access control module is designed with universal functionality to handle multiple storage modes (OTP, MTP, PUF) and different data types (CSP, configuration data) through a single unified interface. The characterization mechanism provides universal access control across all memory operations regardless of the specific mode or data type.
2Measurement precision
If detailed characterization is maintained for each data set, then access control precision is improved, but memory overhead increases
Solution Approach 1:
The characterization data is segmented into two levels: predefined characterizations stored in the link table that apply to multiple data sets, and specific characterizations for individual CSP data sets. This segmentation allows most data to use shared predefined characterizations (reducing overhead) while maintaining precise control where needed.
Solution Approach 2:
The system changes the parameter representation from storing full characterization details for each data set to storing compact identifiers (pointers to predefined characterizations) in the link table. This parameter transformation significantly reduces memory overhead while preserving access control precision through the identifier-to-characterization mapping.
3Device complexity
If traditional access control methods are used without data characterization, then device simplicity is maintained, but security against illicit access techniques deteriorates
Solution Approach 1:
The system performs preliminary characterization of data sets and stores access control parameters in the link table before actual memory operations occur. The access control module validates requests against these pre-established characterizations, providing security through advance preparation rather than complex runtime checks.
Solution Approach 2:
The link table acts as an intermediary structure between the memory array and access control logic. It stores characterization data that mediates the validation process, allowing the system to maintain simplicity in the core memory structure while enhancing security through the intermediate characterization layer.
Data Source
AI summary
A secure microcontroller for a secure data storage device can utilize two-terminal non-volatile memory for enhanced security and component density. The secure microcontroller can operate portions of the two-terminal memory in different modes, such as OTP, rewritable or MTP, physical unclonable function PUF and so forth, and discriminate among data access requests according to data characterizations defined for data parameters stored at the secure storage device. A link table maintained by the secure microcontroller can correlate these characterizations with distinct data parameters. In some embodiments of the present disclosure, the secure microcontroller can also maintain predefined characterizations that are common to many data sets. In these embodiments, the link table can simply correlate many of the data sets to one of the predefined characterizations and significantly reduce the overhead involved in characterizing many distinct data parameters.


