Authenticator Asymmetric Key Management for NAND Flash Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication methods for devices, such as NAND flash memory, rely on shared secret information that can be compromised if leaked, leading to potential illegitimate use and tampering, especially in environments where tamper-resistance is low.
Innovation Solution
A method involving an authenticator and an authenticatee, where the NAND flash memory stores encrypted secret identification information and key management information, and the host device decrypts this information using a family key, ensuring asymmetric secret levels and preventing illegitimate use even if the host device's information is leaked.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If shared secret information is used for authentication, then authentication can be performed, but security is compromised when the secret is leaked
Solution Approach 1:
The patent implements asymmetric key management where the NAND flash memory stores encrypted secret identification information and key management information with different security levels. The host device holds a family key at a lower security level, while the NAND flash memory maintains higher security through encrypted storage. This asymmetric structure ensures that even if the host device's key is leaked, the NAND flash memory's security remains intact, preventing disguise and illegitimate use.
2Reliability
If higher tamper-resistance is maintained for NAND flash memory, then security is improved, but device complexity increases
Solution Approach 1:
The patent segments the authentication system into two distinct parts: the host device that manages lower-security keys and the NAND flash memory that stores encrypted information with higher security. This segmentation allows each component to operate at appropriate security levels, simplifying the overall system architecture while maintaining high tamper-resistance for the NAND flash memory through encrypted storage of secret identification information.
3Reliability
If asymmetric secret levels are implemented, then prevention of illegitimate use is improved, but manufacturing complexity increases
Solution Approach 1:
The patent uses encrypted copies of secret identification information stored in the NAND flash memory. The host device holds a family key that can decrypt these encrypted copies, but the encrypted form maintains the asymmetric security structure. This copying approach enables the host device to access authentication information without compromising the higher security level maintained in the NAND flash memory, facilitating manufacturing while preventing illegitimate use.
Data Source
AI summary
According to one embodiment, a method for authenticating a device, wherein the device holds secret identification information, encrypted secret identification information, and key management information, and an authenticator holds an identification key, the method includes reading, by the authenticator, the encrypted secret identification information and the key management information from the device, and obtaining, by the authenticator, a family key by using the key management information, the family key being capable of being decrypted with the identification key. The method further includes obtaining, by the authenticator, the secret identification information by decrypting the encrypted secret identification information with the family key.


