Secure Non-Volatile Memory Double-Bit Error Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting the confidentiality and security of data in non-volatile memory, such as FLASH-type memory, are inadequate, particularly during the boot sequence of electronic circuits, as they fail to effectively address potential errors or attacks that could compromise critical data like cipher keys.
Innovation Solution
A method involving the loading of a security parameter and its associated error-correcting code into a computation circuit, where errors are detected, and if two bits are erroneous, a default secure value is loaded, triggering countermeasures like transmitting signals to control circuits to execute protective actions, including resetting the system or replacing cipher keys with dummy values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If error-correcting codes are used to detect and correct single-bit errors in security parameters, then data integrity is improved, but the system becomes vulnerable to undetected double-bit errors that could compromise security
Solution Approach 1:
The patent implements a dual-layer error detection mechanism where error-correcting codes handle single-bit errors and an additional double-error detection mechanism handles double-bit errors. This prior cushioning approach ensures that both types of errors are anticipated and managed before they can compromise system security, allowing the system to maintain reliable operation even in the presence of multiple error types.
2Reliability
If the system loads default secure values when errors are detected, then security is maintained, but system productivity decreases due to repeated error handling and countermeasure execution
Solution Approach 1:
The patent pre-loads default secure values into the system before the boot sequence begins. This preliminary action ensures that when errors are detected during boot, the system can immediately use the pre-prepared secure defaults without needing to perform time-consuming error handling routines, thus maintaining both security and boot sequence efficiency.
3Reliability
If countermeasures are executed upon detecting suspicious events, then system security is enhanced, but device complexity increases due to additional control circuits and monitoring mechanisms
Solution Approach 1:
The patent combines the error detection, error correction, and countermeasure execution functions into an integrated control mechanism. The same control circuit that manages error-correcting codes also handles double-error detection and triggers countermeasures, thereby enhancing security while minimizing the increase in device complexity through functional consolidation.
Data Source
AI summary
The present description concerns a method comprising: the loading, from a non-volatile memory of a circuit to a computation circuit, of a first security parameter of the circuit and of a first error-correcting code stored in association with the first security parameter; the verification, by the computation circuit, of the first security parameter and of the first error-correcting code to determine whether one or a plurality of the bits of the security parameter are erroneous; and if it is determined that two bits of the security parameter are erroneous, the loading of a default value of the first parameter into a register.


