Dual-Zone Memory Architecture for Secure Information Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional secure information processing methods are vulnerable to security breaches as they store and manage secure information in a non-secure zone, requiring users to manage multiple secure information sets for each application, leading to instability and increased security risks.

Innovation Solution

An electronic device with a dual-zone memory architecture, where a secure zone with higher security stores extracted secure information from incoming data, while a normal zone processes and stores token information, enhancing security and simplifying management through application mapping.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If secure information is stored in a non-secure zone, then ease of operation is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of secure information managementVSAvoidsecurity reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The memory is divided into a normal zone for general application operations and a secure zone for storing secure information. This segmentation isolates sensitive data from potential security breaches in the normal zone while maintaining ease of access through the secure enclave, resolving the contradiction between operational ease and security reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure enclave acts as an intermediary between the normal zone applications and the secure information storage. It provides a secure interface that allows applications to access secure information without direct exposure to security risks, maintaining both ease of operation and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If separate secure information is requested for each application, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveapplication-specific secure information accessVSAvoidsecure information management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The secure zone serves as a universal storage location that can provide secure information to multiple different applications. Instead of requiring separate secure information management for each application, the secure zone provides a unified interface that adapts to different application needs, reducing management complexity while maintaining adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If secure information is stored in a non-secure zone, then ease of manufacture is improved, but security reliability deteriorates

Engineering Contradiction:
Improveease of secure information storage implementationVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The memory architecture is segmented into normal and secure zones, allowing secure information to be stored in a dedicated secure zone with higher security guarantees. This segmentation is implemented at the memory level, maintaining ease of manufacture while significantly improving security reliability through hardware-supported isolation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10581833B2Electronic device and method for processing secure information
Publication Date: 2020.03.03 SAMSUNG ELECTRONICS CO LTD
  • US10581833B2 patent drawing
  • US10581833B2 patent drawing
  • US10581833B2 patent drawing

AI summary

An electronic device and a method for operating the electronic device are provided. The method includes obtaining first information in a first zone of the electronic device, extracting second information included in the first information in the first zone of the electronic device, and storing the second information in a second zone of the electronic device that has a higher level of security than a level of security of the first zone.