Secure Non-Volatile Memory with Forbidden-Address Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure integrated circuits face challenges in quickly detecting laser and fault attacks on non-volatile memory, particularly when the attack occurs between the memory controller and the memory, making it difficult to prevent unauthorized access to sensitive data.
Innovation Solution
Incorporation of a verify circuit in the non-volatile memory that checks if the internal address bits correspond to forbidden addresses, generating an alarm signal when unauthorized access is detected, and the processing unit is configured to reboot upon receiving this alarm.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a memory controller compares addresses with a table of forbidden addresses to detect attacks, then attack detection capability is improved, but detection speed deteriorates due to time-consuming comparison operations
Solution Approach 1:
The verify circuit pre-calculates and stores the characteristics of forbidden address ranges during circuit design, so that during operation it can quickly determine whether an address falls within forbidden ranges without performing time-consuming comparisons with a table of forbidden addresses
Solution Approach 2:
The patent replaces the software-based address comparison method with a hardware-based verify circuit that uses logical operations to detect forbidden addresses, significantly improving detection speed while maintaining attack detection capability
2Object-affected harmful factors
If the memory is scrambled or encoded to prevent direct reading, then security against direct access is improved, but vulnerability to fault attacks increases as attackers can alter reading to locate sensitive data
Solution Approach 1:
The verify circuit continuously monitors address access patterns and provides immediate feedback through alarm signals when forbidden addresses are accessed, enabling real-time detection of fault attacks even in scrambled or encoded memory configurations
Solution Approach 2:
The verify circuit acts as an intermediary between the address bus and the memory controller, intercepting and verifying addresses before they reach the memory, thus detecting fault attacks without interfering with the scrambled or encoded memory structure
Data Source
Figure 1~2
Figure 3
AI summary
The invention relates to non-volatile memory circuit (300) comprising at least one memory block (310) having a plurality of memory cells (MC1,1 to MCm,n) located at intersection of bit lines (BL1 to BLn) and word lines (WL1 to WLm), and at least one line decoder (350, 380) receiving internal address bits for selecting one word line and one bit line. The non-volatile memory circuit (300) comprises at least one verify circuit (390) receiving the internal address bits and providing an alarm signal (ALARM) when the internal address bits correspond to a forbidden address.