Flash Memory Access Control via Dynamic Code Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional flash memory devices lack effective security measures to control access authorization, allowing unauthorized reading or modification of stored code, particularly in scenarios where electronic piracy is a concern.
Innovation Solution
A memory device with a protection-control structure and control logic that issues a first code to an external device for unlocking protected storage areas, requiring a valid second code response for access, with the first code changing after a predetermined number of unlock procedures to ensure temporary and secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional protection arrangements are used to shield stored data from undesired access operations, then data security is improved, but the access control mechanism lacks effectiveness because it does not verify the identity of devices requesting access authorization changes
Solution Approach 1:
The patent implements a feedback mechanism where the memory device monitors and tracks the identity of external devices requesting access authorization changes. The control logic compares the requesting device's identity against authorized device identifiers, creating a closed-loop verification system that enhances access control effectiveness while maintaining data security.
Solution Approach 2:
The patent introduces an intermediary verification layer between the external device and the protected data. The control logic acts as a mediator that intercepts access requests, verifies device identity against stored authorized identifiers, and only permits access authorization changes when the requesting device is confirmed as authorized. This intermediary mechanism resolves the contradiction by adding verification without compromising the existing protection arrangements.
2Ease of operation
If access authorization can be changed by any external device through simple request, then ease of access is improved, but security is worsened because there is no control on which device is requesting to change access authorization
Solution Approach 1:
The patent applies preliminary action by pre-storing authorized device identifiers within the memory device before any access requests are made. The control logic is pre-configured with a set of valid device identifiers that are stored in a protected location. When access authorization changes are requested, the system performs preliminary verification by comparing the requesting device's identity against these pre-stored authorized identifiers, ensuring that only authorized devices can modify access permissions.
3Adaptability or versatility
If flash memory allows modification of stored code directly in the field, then adaptability is improved, but security is worsened due to vulnerability to electronic piracy and unauthorized reading or corruption of code
Solution Approach 1:
The patent applies local quality by implementing different security characteristics for different regions or aspects of the memory system. The control logic selectively applies identity verification to specific access operations (such as access authorization changes) while allowing other operations to proceed with standard protection. This localized security approach maintains the adaptability of field code modification while protecting critical access control functions from unauthorized manipulation.
Data Source
AI summary
A memory device includes: at least one storage area for storing data; a protection control structure adapted to selectively allow an external device access to the at least one storage area of the memory, the storage area being not freely accessible by the external device if protected; a control logic adapted to identify an access request by the external device to the at least one storage area and cooperating with the protection control structure for managing an unlock procedure for selectively granting the external device at least temporary access rights to the storage area if protected; means for providing a first code to the external device in said unlock procedure; means for receiving a second code from the external device in response to said first code; means for verifying validity of the received second code. The means for verifying validity are adapted to ascertain a correspondence of the second code with the first code based on a predetermined relationship. The control logic instructs the protection control structure to grant access to the storage area if the validity of the received second code has been verified. The first code issued by the memory device to the external device upon receiving an access request is changed after performing predetermined number of unlock procedures.


