Batch Memory Device Control via Server Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current memory device security systems face challenges in securely managing cryptographic keys and transferring privileges, particularly in ensuring the authenticity and integrity of memory devices and preventing unauthorized access.
Innovation Solution
A server system comprising a key management server and an access control server is implemented to securely manage cryptographic keys, authenticate memory devices, and control access, using techniques such as digital signatures and cryptographic hashes to verify identities and authorize operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are stored in the server system for managing memory devices, then the ability to control and authenticate memory devices is improved, but the risk of unauthorized access and security breaches increases
Solution Approach 1:
The server system is divided into two separate components: a key management server that securely stores cryptographic keys and an access control server that handles authentication requests. This segmentation ensures that even if the access control server is compromised, the cryptographic keys remain protected in the key management server, thus maintaining security while enabling authentication capabilities.
2Productivity
If batch transfer control is implemented for multiple memory devices, then the efficiency of privilege transfer is improved, but the complexity of managing batch operations and ensuring individual device integrity increases
Solution Approach 1:
The patent combines multiple individual privilege transfer operations into a single batch operation. The system allows transferring control of multiple memory devices simultaneously by processing them as a group, which improves efficiency. The batch operation includes mechanisms to verify individual device integrity within the batch, managing complexity through unified processing while maintaining device-level security.
3Reliability
If digital signatures and cryptographic hashes are used to verify identities and authorize operations, then the security and integrity of operations are improved, but the computational overhead and processing time increase
Solution Approach 1:
The system performs preliminary authentication and establishes trust relationships before actual memory device operations. Digital signatures and cryptographic hashes are used in advance to verify identities and authorize operations, so that during actual data operations, the verification overhead is minimized. The computational heavy lifting is done beforehand during the authentication phase.
4Adaptability or versatility
If the server system authenticates and controls access to memory devices over computer networks, then the remote management capability is improved, but the vulnerability to network-based attacks such as denial-of-service increases
Solution Approach 1:
The access control server acts as an intermediary between the key management server and client systems over the computer network. It handles authentication requests and validates digital signatures, protecting the key management server from direct network exposure. This intermediary layer filters and manages network traffic, reducing vulnerability to denial-of-service attacks while enabling remote management capabilities.
Data Source
AI summary
A system, method and apparatus to control memory devices over computer networks. For example, a server system establishes a secure authenticated connection with a client computer system to receive a request having a batch identification that is configured in the server system to identify a batch of multiple memory devices. After determining that the client computer system is eligible to control the multiple memory devices in the batch, the server system transmits to the client computer system a response. The response contains control data for each respective memory device in the batch. The control data is based on at least a cryptographic key stored in the server system in association with the respective memory device. Using the control data the client computer system submits a command with a digital signature to the respective memory device, which validates the digital signature prior to execution of the command.


