AI Coprocessor Anomaly Detection for SSD Malware via Electromotive Force

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for detecting malware and ransomware attacks on Solid State Drives (SSDs) face challenges such as latency in threat analysis, memory resource overload, and the need for frequent firmware updates, which can lead to system instability and increased risk of data breaches.

Innovation Solution

The implementation of an Artificial Intelligence Co-processor (AI-Coprocessor) that monitors the Input and Output of NVM Express protocol or AHCI commands on SSDs, measuring electromotive force energy to detect anomalies and generate signature patterns for real-time threat detection and neutralization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firmware or software based solutions are used for malware detection within the SSD controller chipset, then detection capability is provided, but time latency increases due to delays from threat analysis activities

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidtime latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the AI coprocessor from the traditional SSD controller chipset, creating an independent detection device that interfaces with the SSD via standard protocols (SATA, SAS, SATA II, SATA III). This separation allows the coprocessor to perform threat analysis independently without blocking or delaying the main controller's operations, thereby eliminating the time latency problem while maintaining detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The AI coprocessor acts as an intermediary between the SSD controller and the host system. It receives commands and data from the SSD, performs AI-based threat analysis, and communicates results to the host system through standard interfaces. This intermediary role enables parallel processing of detection tasks without interfering with the primary data storage operations, reducing time latency.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional malware detection solutions are implemented, then security monitoring is provided, but memory resources can be overloaded causing information leaks during side channel or DPA attacks

Engineering Contradiction:
Improvesecurity monitoringVSAvoidmemory resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent replaces traditional software-based memory-intensive detection mechanisms with an AI coprocessor that uses specialized hardware circuits and algorithms. The coprocessor employs neural networks and pattern recognition techniques that process data through hardware accelerators rather than consuming large amounts of system RAM, thereby providing security monitoring without overloading memory resources and preventing information leaks during side channel or DPA attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If firmware updates are performed to maintain detection accuracy, then detection capability is improved, but system stability decreases due to increased frequency of updates and potential integration failures

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The AI coprocessor includes a self-learning capability that enables it to automatically update its detection algorithms and patterns without requiring manual firmware updates from the host system. The coprocessor continuously analyzes new threats and adapts its internal models in real-time, performing preliminary learning actions that eliminate the need for frequent firmware updates and maintain system stability while improving detection accuracy over time.

Inventive Principle:
Principle #10Preliminary action

4Reliability

If hardware solutions focusing on integrated circuit flash memory are used, then hardware detection is provided, but data integrity cannot be verified as the methods do not check the integrity of stored data in the solid state drive NAND flash

Engineering Contradiction:
Improvehardware detectionVSAvoiddata integrity
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The AI coprocessor is designed with multi-functionality, capable of performing multiple detection tasks including hardware-level anomaly detection, command pattern analysis, and data integrity verification. It can monitor various aspects of SSD operation such as read/write patterns, error rates, and data checksums, providing comprehensive security coverage that both hardware detection and data integrity verification without requiring separate specialized systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides an additional layer of security against ransomware threats by reducing latency in detection, minimizing memory resource overload, and eliminating the need for frequent firmware updates, thereby enhancing the reliability and performance of SSD security systems.

Implementation Method 1

measuring the electromotive force energy caused by solid state driver during the execution of NVM Express protocol or AHCI commands

Methodology Applied
Scientific EffectElectromotive force: Electromagnetic Induction

Data Source

PatentUS12223039B2Methods and systems using an AI co-processor to detect anomalies caused by malware in storage devices
Publication Date: 2025.02.11 FLEXXON PTE LTD
  • US12223039B2 patent drawing
  • US12223039B2 patent drawing
  • US12223039B2 patent drawing

AI summary

Computer implemented systems and methods for performing electromotive force analysis of a storage device that include a storage device, an Artificial Intelligence Co-processor (AI-Coprocessor) chipset, a thin coil inductor positioned in proximity to a portion of the surface of the storage device for capturing data from electro motive radia generated by the storage device, an analog-to-digital-converter, and at least one probe for communicating the captured data to an analog-to-digital converter. The data is captured by the thin coil inductor and communicated to the analog-to-digital-converter via the at least one probe and the analog-to-digital-converter digitizes the voltage level of the captured data and communicates the results of the digitization and amplification to the Ai-Coprocessor. The Ai-Coprocessor chipset performs analysis of the data to detect any anomalies in the operation of the storage device and outputs those result for further processing. Embodiments include the use of an NVM Express protocol or an AHCI controller engine so it can detect in real time any hardware threats or attacks such as side channel attack, power glitch and any other hardware changes. Embodiments can detect malicious activities such as ransomware, virus and malware, or non-malicious activities by measuring the electromotive force energy caused by anomalous activities.