Secure Memory Bridge Encryption for Unauthorized Access Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer systems fail to maintain the security of system memory contents during and after a reset, allowing unsecure processors or bus masters to gain unauthorized access to system memory.

Innovation Solution

A secure memory system is implemented with a security control module that transmits secure mode signals to place the system in a secure mode, a secure memory bridge that encrypts and decrypts data based on these signals, and a boot processor that manages requests in both secure and unsecure modes, ensuring only authorized access to system memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the system memory is not reset during system reset, then the memory contents are preserved for quick access, but unsecure processors or bus masters can gain unauthorized access to the memory contents

Engineering Contradiction:
Improvememory access speedVSAvoidmemory security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

A secure memory bridge is introduced as an intermediary component between the bus interconnect and system memory. This bridge contains encryption/decryption logic that mediates all access requests, allowing the memory to retain contents while ensuring only authorized secure accesses can read the data. The bridge acts as a security gatekeeper that verifies clearance before allowing memory access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system changes the security parameter of the memory contents by encrypting them when the system enters secure mode. The memory contents themselves are not reset, but their security state is transformed through encryption, making unauthorized access meaningless even if the unsecure processor gains bus access.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If encryption and decryption logic is added to the memory bridge, then memory security is maintained, but the device complexity increases

Engineering Contradiction:
Improvememory securityVSAvoidmemory bridge complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The memory bridge is designed to perform multiple functions: it acts as both a security enforcement mechanism (through encryption/decryption) and a standard memory interface bridge. By making the bridge multi-functional, the patent avoids adding separate dedicated security hardware, thereby managing complexity while achieving security goals.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8239663B2System and method for maintaining the security of memory contents and computer architecture employing the same
Publication Date: 2012.08.07 LSI CORP
  • US8239663B2 patent drawing
  • US8239663B2 patent drawing
  • US8239663B2 patent drawing

AI summary

A secure memory system and a method of maintaining the security of memory contents. One embodiment of the system includes: (1) a security control module configured to transmit a system memory secure mode signal and processor secure mode signal to place the system in a secure mode, (2) a secure memory bridge coupled to the security control and system memory and configured to encrypt and decrypt data associated with the system memory based on a state of the system memory secure mode signal and (3) a boot processor coupled to the security control module and the secure memory bridge and configured to transmit requests to the secure memory bridge in the secure mode and an unsecure mode.