Secure Memory Segmentation for Secret Key Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems for protecting secret keys in secure integrated circuits, such as chip cards, are vulnerable to side channel attacks when these keys are manipulated by the circuit processor, as they transit over shared data buses, and existing methods are insufficient to prevent piracy during processing.

Innovation Solution

A system that isolates secret data by providing them to a logic circuit inaccessible to the processor, using an address decoder to calculate the address of the secret data based on the address of independent second data, ensuring the secret data never transit over the data bus, thus preventing exposure during processing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If secret data are stored in non-volatile memory and accessed by the processor over shared data buses, then the processor can manipulate the secret keys, but the keys become vulnerable to side channel attacks and piracy

Engineering Contradiction:
Improveprocessor accessibility to secret dataVSAvoidvulnerability to side channel attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The memory system is segmented into two distinct parts: a first memory area accessible by the processor for storing non-secret data, and a second memory area inaccessible by the processor for storing secret data. This segmentation allows the processor to operate on secret data indirectly through controlled access mechanisms while preventing direct exposure to the data bus, thus resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A controlled access mechanism acts as an intermediary between the processor and the second memory area. This intermediary enables the processor to manipulate secret data without direct access, using indirect addressing through the first memory area. The intermediary prevents secret data from appearing on the data bus while still allowing processor manipulation, thus eliminating vulnerability to side channel attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secret data are masked by random numbers or protection solutions during processing, then some protection is provided, but secret data still plainly appear in processor registers at certain moments

Engineering Contradiction:
Improveprotection level of secret dataVSAvoidexposure of secret data in registers
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The secret data are extracted from the processor's direct addressable space and placed in a separate, inaccessible memory area. By taking out the secret data from the processor's direct access domain, the invention eliminates their appearance in processor registers, completely preventing exposure to piracy while maintaining processing capability through indirect access mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If secret data are transferred over the shared data bus between memory and processor registers, then the processor can access and manipulate the keys, but the data risk being pirated during transmission

Engineering Contradiction:
Improvedata transfer capabilityVSAvoidpiracy risk during data transmission
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The invention introduces a new dimension of access control by creating a hierarchical memory structure with different access privileges. Secret data reside in a second memory area that is inaccessible to the processor, while a first memory area serves as an interface. This dimensional separation allows data transfer capability to be maintained through controlled indirect access while eliminating the security risk of direct data bus exposure.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS8806109B2Protection of secret keys
Publication Date: 2014.08.12 STMICROELECTRONICS (ROUSSET) SAS
  • US8806109B2 patent drawing
  • US8806109B2 patent drawing
  • US8806109B2 patent drawing

AI summary

A method for protecting at least first data of a non-volatile memory from which the extraction of this first data is triggered by the reading or the writing, by a processor from or into the memory, of second data independent from the first data, said first data being provided to a circuit which the processor cannot access.