Secure SoC Version Directory for External Memory Rollback Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In systems on a chip (SOC) with a secure element, data stored in external memory is vulnerable to attacks like rollback, where old data is reused for fraudulent purposes, and there is a need for a local method to ensure data freshness without remote server connection.
Innovation Solution
A system-on-chip with a secure element that includes a processing unit to control data storage and versioning in external and secure memories, using a dedicated directory to associate object identifiers with current versions, ensuring freshness by comparing these versions and updating them in secure volatile memory.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If data is stored in external rewritable non-volatile memory, then storage capacity and endurance are improved, but data freshness and security are worsened due to vulnerability to rollback attacks
Solution Approach 1:
The patent applies preliminary action by pre-associating version identifiers with data objects before storage in external memory. The processing unit generates and stores version identifiers in a dedicated directory structure within the external memory, enabling future verification of data freshness without requiring remote server connections. This preliminary versioning mechanism allows the system to detect rollback attacks by comparing current version identifiers against stored ones.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of a dedicated directory structure that mediates between the data objects and the verification process. This directory contains version identifier associations that act as intermediaries to verify data freshness, eliminating the need for remote server validation while maintaining security against rollback attacks.
2Reliability
If version identifiers are stored in secure non-volatile memory, then data freshness verification is improved, but device complexity is worsened
Solution Approach 1:
The patent applies segmentation by dividing the version verification functionality into distinct components: data objects stored in external memory, a dedicated directory structure for version identifier associations, and secure non-volatile memory for storing current version identifiers. This segmentation allows each component to have a specific function, simplifying the overall verification process while maintaining reliability.
Solution Approach 2:
The patent uses copying by creating a dedicated directory structure that copies and associates version identifiers with data objects. This directory is then copied or referenced in secure non-volatile memory, allowing verification without duplicating the entire data set. This copying mechanism reduces complexity compared to storing all version information centrally.
3Adaptability or versatility
If external memory is shared with other applications, then memory utilization is improved, but security control is worsened due to independent manipulation
Solution Approach 1:
The patent implements feedback by creating a verification loop where version identifiers are checked against stored values before data operations are permitted. This feedback mechanism provides continuous validation that detects unauthorized manipulations or rollback attempts, allowing the system to reject invalid operations even when memory is shared with other applications. The feedback ensures that data freshness is verified before any critical operations.
Data Source
Figure 1
Figure 2
Figure 3A~3B
AI summary
The invention relates to a system on a chip (10) comprising a secured element (102) comprising a processing unit (1022) that is configured to send instructions to a rewritable non-volatile memory (12) external to the system on a chip and connected thereto, the secured element (102) further comprising a secured non-volatile memory (1024) and a secured volatile memory (1026), the system on a chip (10) being characterized in that the processing unit (1022) is configured to control: - the storage, in the rewritable non-volatile memory (12), of at least one object having a current version, and of a dedicated directory associating an identifier of each object with an identifier of the current version of this object, the dedicated directory further comprising an identifier of its own current version; and - the storage, in the non-volatile memory (1024) of the secured element, of the identifier of the current version of the dedicated directory.