Endpoint Firmware Customization via Secure Memory Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for communication endpoints with secure memory devices in networks lack robustness against counterfeit, tampering, and unauthorized access, particularly in ensuring the integrity and authenticity of data and devices.

Innovation Solution

A security server and memory devices with integrated security features that utilize cryptographic computations and access control mechanisms to validate the identity of memory devices, prevent unauthorized access, and maintain data integrity, eliminating the need for physical SIM cards by securely configuring and authenticating endpoints for services.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical SIM cards are used for authentication, then device identity verification is achieved, but device complexity and operational burden increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication functionality from physical SIM cards and implements it within the device's secure memory device. The identity verification process is removed from external physical media and integrated into the device's internal secure storage, eliminating the need for removable SIM cards while maintaining authentication reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a virtual representation of the SIM card functionality within the secure memory device. Instead of using physical SIM cards, the system copies and emulates SIM card authentication operations in software within the device's secure memory, achieving the same authentication purpose without physical media

Inventive Principle:
Principle #26Copying

2Reliability

If secure authentication mechanisms are implemented, then data integrity and authenticity are improved, but system complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (authentication, encryption, integrity verification) into a single secure memory device. By merging these previously separate security mechanisms into one integrated component, the system achieves robust data integrity and authenticity protection while reducing overall system complexity

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure memory device is designed to perform multiple security-related functions including authentication, data encryption, integrity verification, and identity management. This multi-functional approach allows a single component to provide comprehensive security protection, improving data integrity without proportionally increasing system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If online firmware store is implemented, then endpoint customization and service access are improved, but security vulnerabilities to counterfeit and tampering increase

Engineering Contradiction:
Improveendpoint customizationVSAvoidcounterfeit and tampering
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by establishing cryptographic verification mechanisms before allowing firmware updates or customizations from the online store. The secure memory device pre-configures authentication credentials that verify the authenticity of downloaded firmware, preventing counterfeit and tampered software from being installed

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system implements a feedback mechanism where the secure memory device continuously verifies the authenticity of firmware and software updates obtained from the online firmware store. Cryptographic signatures and authentication protocols provide real-time feedback on the integrity of downloaded content, blocking any counterfeit or tampered firmware from being installed

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12039318B2Endpoint customization via online firmware store
Publication Date: 2024.07.16 MICRON TECHNOLOGY INC
  • US12039318B2 patent drawing
  • US12039318B2 patent drawing
  • US12039318B2 patent drawing

AI summary

A server system to customize firmware of an endpoint via an online firmware store in connection with validating authenticity of the endpoint. For example, a customized version of firmware can be ordered for the endpoint prior to the use of the endpoint. After receiving a request having identity data generated by a memory device configured in the endpoint, the server system can determine, based on a secret of the memory device, the authenticity of the endpoint having the current firmware. An update to firmware stored in the memory device and executed in the endpoint to generate the request is identified. The server system generates a verification code for a command executable in the memory device to perform the update. After receiving the command and the verification code, the memory device validates the verification code to determine whether to execute the command for firmware update.