Flash Drive Smart Card Module Security Partitioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

USB flash memory devices lack robust security measures, making them vulnerable to data theft and unauthorized access, especially when used on unfamiliar computers, and existing encryption solutions are not universally compatible or secure against advanced hacking techniques.

Innovation Solution

Incorporating a smart card module that operates in conjunction with the USB flash drive microcontroller to provide enhanced security features, including authentication and cryptographic services, and managing partition sizes and parameters securely, ensuring that sensitive data is protected and only accessible with authorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a smart card module is integrated with a flash memory controller to enhance security, then data security and authentication capability are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the flash memory controller and smart card module into a single integrated device, allowing the flash drive to function both as storage and as a security token. This merging eliminates the need for separate security devices while maintaining enhanced security through the smart card's authentication capabilities and encrypted data storage.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If partition sizes are made dynamically adjustable between secure and non-secure areas, then adaptability and user flexibility are improved, but device complexity and security management difficulty increase

Engineering Contradiction:
Improvepartition flexibilityVSAvoidpartition management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic partition resizing capability where the secure and non-secure partition sizes can be adjusted based on user needs. The system allows users to modify partition allocations while maintaining security boundaries, enabling the device to adapt to different storage requirements without compromising the security model.

Inventive Principle:
Principle #15Dynamics

3Reliability

If encryption is implemented at the file system level with smart card authentication, then data protection against unauthorized access is improved, but processing overhead and operation time increase

Engineering Contradiction:
Improvedata protectionVSAvoidauthentication and encryption processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs encryption and authentication operations during the file system initialization and mount processes, before actual data access occurs. By pre-establishing secure contexts and verifying authentication credentials upfront, the system minimizes the impact of security processing on subsequent data operations, as the cryptographic framework is already in place when users access files.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8307131B2System and method for drive resizing and partition size exchange between a flash memory controller and a smart card
Publication Date: 2012.11.06 THALES DIS FRANCE SA
  • US8307131B2 patent drawing
  • US8307131B2 patent drawing
  • US8307131B2 patent drawing

AI summary

A system and method to control a device having at least one configurable parameter. Enumerating the device as a first peripheral device and as a second peripheral device wherein the first peripheral device corresponds to a first microcontroller connected to a storage medium and the second peripheral device corresponds to a second microcontroller. Controlling the at least one configurable parameter of the first microcontroller with respect to the storage medium by the second microcontroller. On initialization of the device, transmitting the at least one configurable parameter from the second microcontroller to the first microcontroller. Other systems and methods are disclosed.