Digital Memory Dynamic Partitioning for Secure Multi-User Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital memory technologies, such as memory cards, lack mechanisms for users to securely manage and share data, particularly in untrusted environments, and do not allow users to set their own security keys, leading to vulnerabilities in data protection and access control.

Innovation Solution

A method and system for dynamically partitioning digital memory into private areas that users can securely allocate and access using a secure session channel, with users able to self-allocate areas and manage their own keys, employing symmetric and asymmetric crypto-algorithms to protect communication and data, and allowing for multi-user access while preventing unauthorized use.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If digital memory is used in untrusted environments with multiple users, then data sharing capability is improved, but security and access control deteriorate

Engineering Contradiction:
Improvedata sharing capabilityVSAvoidsecurity and access control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The digital memory is divided into multiple private areas, each securely allocated to a specific user. This segmentation allows multiple users to share the same memory device while maintaining individual security boundaries, thus improving data sharing capability without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure session channel acts as an intermediary between users and the digital memory system. This channel provides authenticated access control, enabling users to safely access their allocated private areas while preventing unauthorized access to other users' data, thus resolving the security concern in multi-user environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If security keys are pre-configured by the system, then access control is simplified, but user autonomy and security customization deteriorate

Engineering Contradiction:
Improveaccess control simplicityVSAvoiduser autonomy and security customization
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

Users are empowered to self-allocate their own private areas within the digital memory and manage their own access keys. This self-service approach allows users to customize their security settings and data organization according to their specific needs, thereby improving user autonomy while maintaining systematic access control through the secure session channel.

Inventive Principle:
Principle #25Self-service

3Device complexity

If traditional memory protection mechanisms are used, then implementation simplicity is maintained, but protection against external attacks deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidvulnerability to external attacks
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The system implements dynamic secure session channels that are established and torn down based on user needs. This dynamic approach provides robust protection against external attacks through encrypted communication and authenticated access, while maintaining implementation simplicity by using standardized cryptographic protocols within the secure session framework.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8789195B2Method and system for access control and data protection in digital memories, related digital memory and computer program product therefor
Publication Date: 2014.07.22 TELECOM ITALIA SPA
  • US8789195B2 patent drawing
  • US8789195B2 patent drawing
  • US8789195B2 patent drawing

AI summary

A digital memory such as a memory card for mobile communication equipment, is adapted to be accessed by a plurality of users and have protected data stored therein. The memory is dynamically partitionable in private memory areas for storing data therein and has associated therewith a secrecy tool for securely allocating to the users respective private areas and permitting the users to access the respective private areas via a secure session channel to perform read/write commands in the respective private areas. Typically, the memory/card includes: a card interface controller for managing a physical communication layer between the digital memory and external host equipment, an internal memory having associated therewith a hardware lock to control access to the internal memory, a set of cryptographic modules to manage the secure session channel between the users and the digital memory, and a memory certificate for certifying a public key associated with the digital memory.