Blockchain-Based Firmware Attestation for Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for improved reliability and security in storage devices, particularly in ensuring the integrity of firmware operations across devices, which existing technologies have not adequately addressed.

Innovation Solution

The implementation of blockchain technology for device authentication, firmware attestation, and updates, where storage devices use a blockchain ledger to verify the authenticity and integrity of firmware by sharing public keys and measurement values, enabling secure and reliable operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used for storage devices, then device communication is simple, but security and reliability of firmware operations are insufficient

Engineering Contradiction:
Improvefirmware operation integrityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a blockchain ledger as an intermediary component that stores public keys and measurement values of firmware operations. This mediator enables secure verification between storage devices without requiring complex point-to-point authentication mechanisms, as the blockchain serves as a trusted third-party repository for cryptographic verification data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The blockchain ledger performs multiple functions simultaneously: it stores public keys for authentication, maintains measurement values for firmware integrity verification, and provides a decentralized trust mechanism. This multi-functional approach consolidates what would otherwise require separate systems into a single universal verification infrastructure.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If blockchain technology is implemented for device authentication and firmware verification, then security and trustworthiness are improved, but system complexity and computational overhead increase

Engineering Contradiction:
Improvedevice authentication securityVSAvoidblockchain integration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-storing public keys and firmware measurement values in the blockchain ledger before actual authentication operations. This advance preparation allows storage devices to quickly verify firmware integrity without performing complex cryptographic computations in real-time, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic hashing to create simplified representations (copies) of firmware data in the form of measurement values stored in the blockchain. Instead of verifying entire firmware images during authentication, the system verifies these compact hash copies, dramatically reducing computational overhead while maintaining verification security.

Inventive Principle:
Principle #26Copying

3Reliability

If firmware integrity verification is performed across multiple storage devices, then malicious software persistence is reduced, but authentication time and processing overhead increase

Engineering Contradiction:
Improvemalicious software detectionVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces complex mechanical verification processes with cryptographic substitution. Instead of physically inspecting or manually verifying firmware integrity across devices, the system uses cryptographic hash functions and blockchain-based verification mechanisms that automatically detect malicious modifications, significantly reducing authentication time while improving detection capability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4181005A1Storage device, storage system having the same and method of operating the same
Publication Date: 2023.05.17 SAMSUNG ELECTRONICS CO LTD
  • EP4181005A1 patent drawingFigure 1
  • EP4181005A1 patent drawingFigure 2
  • EP4181005A1 patent drawingFigure 3

AI summary

Storage systems including a host device, a switch device, and storage devices connected to the host device through the switch device are described. Moreover, techniques for operating a host device, a switch device, and/or one or more storage devices are also described. One or more aspects of the present disclosure may provide for improved storage devices and systems via implementation of blockchain networks. In some cases, a storage device itself may be a node of a blockchain network, or a system including a storage device may be a node of a blockchain network. One or more aspects of the present disclosure provide for attestation of firmware (e.g., qualification verification to identify whether the firmware is operating normally) performed using the blockchain. Further, one or more aspects of the present disclosure describe techniques for performing device authentication between devices, for performing qualification verification for firmware, for performing firmware updates, etc.