Secure Memory Transducer for Runtime Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing trust mechanisms, such as the Silicon Root of Trust (SROT), primarily focus on establishing initial trust during the startup of an electronic device but fail to provide adequate protection during runtime, leaving embedded systems vulnerable to compromise.

Innovation Solution

A secure memory transducer is introduced to support secure measurements by a validator system during runtime or initial start processes. This transducer generates cryptographic values based on information from selected memory regions, providing an isolation barrier that prevents unauthorized access to memory contents.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a trust mechanism like Silicon Root of Trust is used to establish initial trust during startup, then initial trust is established, but runtime security protection is insufficient and the system remains vulnerable to compromise

Engineering Contradiction:
Improveruntime securityVSAvoidtrust mechanism coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary actions by measuring and validating embedded system information at multiple stages: during initial startup using Silicon Root of Trust, and continuously during runtime through secure memory transducers. This preliminary validation of memory contents, configuration data, and system state at various checkpoints ensures trust is established before any potential compromise can occur, resolving the contradiction between initial trust establishment and runtime security protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces secure memory transducers as intermediary components between the validator system and the embedded system memory. These transducers act as mediators that enable the validator system to access and measure memory contents without direct access to the embedded system, providing runtime security verification while maintaining system isolation and vulnerability to compromise.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If direct access to memory regions is provided to the validator system, then validation can be performed, but unauthorized access and security risks increase

Engineering Contradiction:
Improvevalidation capabilityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent employs secure memory transducers as intermediary components that stand between the validator system and the embedded system memory. These transducers enable the validator system to obtain cryptographic values and measure memory contents without establishing direct access pathways, thereby maintaining validation capability while preventing unauthorized access and reducing security risks through controlled, monitored access only.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces direct mechanical/memory-level access with cryptographic substitution. Instead of allowing direct reading of memory contents, the system uses secure memory transducers to generate and transmit cryptographic hashes and values that represent the memory state. This substitution maintains validation integrity while eliminating the harmful direct access pathway, as the validator system receives only processed cryptographic data rather than raw memory contents.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250190369A1Cryptographic computations for memory regions
Publication Date: 2025.06.12 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20250190369A1 patent drawing
  • US20250190369A1 patent drawing
  • US20250190369A1 patent drawing

AI summary

In some examples, a controller receives, from a validator system in an electronic device, input information including address information identifying a memory region in a memory to validate. The memory is associated with a target system to be validated and the memory is inaccessible to the validator system. Based on the address information, the controller retrieves information from the memory region in the memory, where the controller provides a barrier that prevents access of the retrieved information by the validator system. The controller computes a cryptographic value based on the retrieved information, and the controller sends, to the validator system, an output based on the cryptographic value as a response to the input information.