Secure SoC Version Directory for External Memory Rollback Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In systems on a chip (SOC) with a secure element, data stored in external memory is vulnerable to attacks like rollback, where old data is reused for fraudulent purposes, and there is a need for a local method to ensure data freshness without remote server connection.

Innovation Solution

A system-on-chip with a secure element that includes a processing unit to control data storage and versioning in external and secure memories, using a dedicated directory to associate object identifiers with current versions, ensuring freshness by comparing these versions and updating them in secure volatile memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If data is stored in external rewritable non-volatile memory, then storage capacity and endurance are improved, but data freshness and security are worsened due to vulnerability to rollback attacks

Engineering Contradiction:
ImproveenduranceVSAvoiddata freshness
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-associating version identifiers with data objects before storage in external memory. The processing unit generates and stores version identifiers in a dedicated directory structure within the external memory, enabling future verification of data freshness without requiring remote server connections. This preliminary versioning mechanism allows the system to detect rollback attacks by comparing current version identifiers against stored ones.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism in the form of a dedicated directory structure that mediates between the data objects and the verification process. This directory contains version identifier associations that act as intermediaries to verify data freshness, eliminating the need for remote server validation while maintaining security against rollback attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If version identifiers are stored in secure non-volatile memory, then data freshness verification is improved, but device complexity is worsened

Engineering Contradiction:
Improvedata freshness verificationVSAvoidmemory structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the version verification functionality into distinct components: data objects stored in external memory, a dedicated directory structure for version identifier associations, and secure non-volatile memory for storing current version identifiers. This segmentation allows each component to have a specific function, simplifying the overall verification process while maintaining reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses copying by creating a dedicated directory structure that copies and associates version identifiers with data objects. This directory is then copied or referenced in secure non-volatile memory, allowing verification without duplicating the entire data set. This copying mechanism reduces complexity compared to storing all version information centrally.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If external memory is shared with other applications, then memory utilization is improved, but security control is worsened due to independent manipulation

Engineering Contradiction:
Improvememory sharingVSAvoidunauthorized data manipulation
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback by creating a verification loop where version identifiers are checked against stored values before data operations are permitted. This feedback mechanism provides continuous validation that detects unauthorized manipulations or rollback attempts, allowing the system to reject invalid operations even when memory is shared with other applications. The feedback ensures that data freshness is verified before any critical operations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP4032000B1System on chip and method ensuring freshness of data stored in external memory
Publication Date: 2025.08.06 IDEMIA FRANCE SAS
  • EP4032000B1 patent drawingFigure 1
  • EP4032000B1 patent drawingFigure 2
  • EP4032000B1 patent drawingFigure 3A~3B

AI summary

The invention relates to a system on a chip (10) comprising a secured element (102) comprising a processing unit (1022) that is configured to send instructions to a rewritable non-volatile memory (12) external to the system on a chip and connected thereto, the secured element (102) further comprising a secured non-volatile memory (1024) and a secured volatile memory (1026), the system on a chip (10) being characterized in that the processing unit (1022) is configured to control: - the storage, in the rewritable non-volatile memory (12), of at least one object having a current version, and of a dedicated directory associating an identifier of each object with an identifier of the current version of this object, the dedicated directory further comprising an identifier of its own current version; and - the storage, in the non-volatile memory (1024) of the secured element, of the identifier of the current version of the dedicated directory.