Authenticated Memory Controller for Secure Data Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional memory devices, such as flash memory, lack the capability to securely perform sensitive tasks and operations on data without exposing the data to the host processor, which can compromise security and increase the workload of the host processor.

Innovation Solution

A memory component is employed as a slave device that can authenticate and perform tasks, functions, and operations on sensitive data without providing the data to the host processor, allowing it to securely process and store results while keeping the data secure within the memory component.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the host processor processes sensitive data directly, then the host processor can perform tasks on the data, but data security is compromised and host workload increases

Engineering Contradiction:
Improvedata securityVSAvoidhost processor workload
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an authenticated memory device as an intermediary between the host processor and sensitive data. The memory device includes a controller that authenticates the host and performs data processing operations locally, acting as a mediator that prevents sensitive data from being exposed to the host while still enabling computational tasks. This resolves the contradiction by maintaining data security (improving reliability) while reducing host processor workload (improving productivity).

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The memory device is designed to perform data processing operations autonomously without requiring the host processor to directly access or process the sensitive data. The controller within the memory device authenticates requests and executes computational tasks locally, enabling the system to serve itself and reducing the burden on the host processor while maintaining data security.

Inventive Principle:
Principle #25Self-service

2Adaptability or versatility

If the memory device operates as a conventional storage device, then data can be stored and retrieved, but the device functionality is limited and security capabilities are insufficient

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity capability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent transforms the memory device from a simple storage device into a multi-functional system. The controller is designed to perform multiple functions including data storage, authentication of host processors, cryptographic operations, and data processing tasks. This universality allows the device to adapt to different operational modes and security requirements, thereby improving both adaptability and security capability simultaneously.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The memory device changes its operational parameters dynamically based on authentication results and command types. The controller can switch between different security levels, processing modes, and access permissions. This ability to change parameters allows the device to provide enhanced security capabilities while maintaining versatile functionality for different computational tasks.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS9767303B2Authenticated memory and controller slave
Publication Date: 2017.09.19 MONTEREY RESEARCH LLC
  • US9767303B2 patent drawing
  • US9767303B2 patent drawing
  • US9767303B2 patent drawing

AI summary

Systems and methods that can facilitate the utilization of a memory as a slave to a host are presented. The host and memory can provide authentication information to each other and respective rights can be granted based in part on the respective authentication information. The host can determine the available functionality of the memory. The host can activate the desired functionality in the memory and can request memory to perform the desired function(s) with regard to data stored in the memory. An optimized controller component in the memory can facilitate performing the desired function(s) associated with the data to generate a result. The result can be provided to the host, while the data and associated information utilized to generate the result can remain in the memory and are cannot be accessed by the host.