Hardware State Switching for Secure Memory Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for securing key data in computer systems, such as password hash values and random keys, rely on expensive security chips like EEPROMs to ensure access limitations, increasing implementation costs and seeking a more cost-effective solution that maintains data security and extensibility.
Innovation Solution
Implement a method for state switching between hardware systems, where one hardware system sends an access state switching instruction to another, switching the memory unit from an un-protected to a protected state or vice versa, ensuring secure access based on operation states, thereby preventing malicious access and reducing costs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a specific EEPROM with security protection function is used to store key data, then data security is improved, but implementation cost increases
Solution Approach 1:
The patent applies universality by enabling ordinary memory devices (such as RAM, ROM, flash memory) to perform security protection functions through software-based access state switching mechanisms. Instead of requiring specialized security chips, the system makes general-purpose memory devices multi-functional by adding access control capabilities through state switching instructions, thereby reducing hardware costs while maintaining security.
Solution Approach 2:
The patent implements parameter changes by dynamically switching the access state of memory devices between protected and unprotected states based on operational conditions. The memory device's access parameters (read/write permissions) are changed through state switching instructions triggered by specific events (e.g., power-on, password verification), allowing the same memory device to provide different security levels at different times without requiring specialized hardware.
2Reliability
If access control is implemented on key data using a security chip, then security level is improved, but device complexity increases
Solution Approach 1:
The patent reduces device complexity by making the memory device itself multi-functional, combining both storage and access control functions in a single component. The memory device can operate in different modes (protected/unprotected states) based on received instructions, eliminating the need for separate security chips and reducing overall system complexity while maintaining security capabilities.
Solution Approach 2:
The patent applies self-service by enabling the memory device to autonomously switch between protected and unprotected states based on instructions received from the system. The memory device monitors its own access state and automatically adjusts its permissions without requiring external security chip intervention, thereby simplifying the system architecture while maintaining security control.
3Ease of manufacture
If conventional storage media are used for key data, then implementation cost is reduced, but access security deteriorates
Solution Approach 1:
The patent resolves this contradiction by dynamically changing the access parameters of conventional memory devices. The memory devices maintain their low-cost characteristics while their access security parameters are switched between protected and unprotected states based on operational conditions, allowing ordinary hardware to provide enhanced security without increasing implementation costs.
Solution Approach 2:
The patent applies dynamics by making the access control state of memory devices dynamic rather than static. The memory devices can transition between different access states (protected/unprotected) during operation based on system conditions, allowing conventional low-cost hardware to adapt its security level dynamically without requiring expensive specialized security hardware.
Data Source
AI summary
Disclosed are methods and systems for state switching. The method is applied to a first hardware system. The first hardware system is connected with a second hardware system. The first hardware system has a first operation state and a second operation state. The second hardware system includes a memory unit. The memory unit has a first access state and a second access state. The memory unit is in the first access state currently. The method includes: the first hardware system sends an access state switching instruction to the second hardware system when the first hardware system enters the second operation state from the first operation state, wherein, the access state switching instruction is adapted to switch the memory unit of the second hardware system from the first access state to the second access state. The application of the present invention can ensure the security of key data, avoid the access of key data by malicious software, reduce the implementation costs and has a higher extensibility.


