Semiconductor Nonvolatile Memory Security State Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing semiconductor devices lack effective protection mechanisms for on-chip nonvolatile memory devices during system debug and real machine operation, allowing unauthorized access and modification.

Innovation Solution

A semiconductor device with three security states (unprotected, protection unlocked, and protection locked) is implemented, where the security state transitions are controlled by secret information and authentication, allowing authorized access and protection cancellation under predetermined authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If protection is set for the nonvolatile memory device during system debug, then security against unauthorized access is improved, but the ability to rewrite the memory for debugging purposes deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoiddebugging capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic security states (unprotected state and protected state) that can transition based on authentication. During debugging, the system can be in an unprotected state allowing free rewriting. When security is needed, it transitions to a protected state. This dynamic switching resolves the contradiction by making the protection level adaptable to the current operational context rather than fixed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent introduces an authentication mechanism as an intermediary between the desire for protection and the need for debugging access. The authentication result acts as a mediator that determines whether to allow rewriting operations. This intermediary layer enables controlled access where legitimate debugging can proceed while preventing unauthorized modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the security state is set to protected during real machine operation, then unauthorized reading or rewriting is prevented, but the ability to update programs or data deteriorates

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidprogram update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically adjusts its security level based on operational needs. During normal real-machine operation, the memory is in a protected state preventing unauthorized access. When program updates are needed, the system can transition to an unprotected state after proper authentication, allowing updates while maintaining security during regular operation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements preliminary authentication before allowing state transitions from protected to unprotected. This preliminary action ensures that only authorized entities can temporarily disable protection for legitimate updates, thereby maintaining both security during operation and adaptability for updates when needed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication using secret information is required for rewriting, then security against third-party access is improved, but the complexity of the access control mechanism increases

Engineering Contradiction:
Improvesecurity against unauthorized rewritingVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication logic as a separate, dedicated mechanism within the memory control unit. Rather than distributing security checks throughout the system, the authentication function is isolated and specialized. This extraction improves security reliability while managing complexity by concentrating it in a dedicated component with a single responsibility.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The memory control unit performs self-service authentication by internally comparing provided secret information against stored authentication data. This self-service approach eliminates the need for external authentication hardware or complex external verification protocols, thereby improving security while keeping the mechanism relatively simple and self-contained.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9116840B2Semiconductor device and data processing method
Publication Date: 2015.08.25 RENESAS ELECTRONICS CORP
  • US9116840B2 patent drawing
  • US9116840B2 patent drawing
  • US9116840B2 patent drawing

AI summary

A semiconductor device has: as security states to which the nonvolatile memory device can transition, an unprotected state in which, when secret information is not set in the nonvolatile memory device, rewriting the nonvolatile memory device is permitted, and reading the stored information is permitted; a protection unlocked state in which, when the secret information is set in the nonvolatile memory device, rewriting the nonvolatile memory device is permitted on condition that a result of authentication using the secret information is correct, and reading the stored information is permitted; and a protection locked state in which, when the secret information is set in the nonvolatile memory device, rewriting the nonvolatile memory device is inhibited until correctness as a result of authentication using the secret information is confirmed, and reading the stored information is inhibited under a predetermined condition.