Flash Memory Device Integrating PUF-Based Identity Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security frameworks for IoT devices face challenges in providing robust, cost-effective, and power-efficient identity verification and key management, especially in small computing devices where traditional hardware security modules like TPMs are impractical.

Innovation Solution

Integration of hardware-based roots of trust into flash memory devices for IoT devices, leveraging the Device Identity Composition Engine (DICE) and Robust Internet-of-Things (RIoT) architecture to generate cryptographic identities and manage keys, enabling secure device provisioning and attestation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional hardware security modules like TPMs are used for IoT devices, then security functionality is improved, but device size, cost, and power consumption increase making them impractical for small computing devices

Engineering Contradiction:
Improvesecurity functionalityVSAvoiddevice size
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the security functions traditionally provided by separate hardware security modules (TPM, HSM) directly into the flash memory device. This integration merges storage and security functions into a single component, eliminating the need for additional security hardware while maintaining security functionality for small IoT devices

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The flash memory device is designed to perform multiple functions: data storage, code execution, and cryptographic security operations. By making the flash memory universal and multi-functional, the patent eliminates the need for dedicated security modules, reducing device complexity while maintaining security capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If traditional hardware security modules like TPMs are used for IoT devices, then security functionality is improved, but implementation cost increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent combines the security functions traditionally provided by separate hardware security modules (TPM, HSM) directly into the flash memory device. This integration merges storage and security functions into a single component, eliminating the need for additional security hardware while maintaining security functionality for small IoT devices

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The flash memory device is designed to perform multiple functions: data storage, code execution, and cryptographic security operations. By making the flash memory universal and multi-functional, the patent eliminates the need for dedicated security modules, reducing device complexity while maintaining security capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If traditional hardware security modules like TPMs are used for IoT devices, then security functionality is improved, but power consumption increases

Engineering Contradiction:
Improvesecurity functionalityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent combines the security functions traditionally provided by separate hardware security modules (TPM, HSM) directly into the flash memory device. This integration merges storage and security functions into a single component, eliminating the need for additional security hardware while maintaining security functionality for small IoT devices

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The flash memory device is designed to perform multiple functions: data storage, code execution, and cryptographic security operations. By making the flash memory universal and multi-functional, the patent eliminates the need for dedicated security modules, reducing device complexity while maintaining security capabilities

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Device complexity

If hardware-based roots of trust are integrated into flash memory devices, then device complexity is reduced, but security requirements for the flash memory increase

Engineering Contradiction:
Improveimplementation complexityVSAvoidsecurity requirements
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the security functionality into distinct cryptographic modules within the flash memory device, including key generation, key storage, and cryptographic operation modules. This segmentation allows each module to be optimized for its specific function while maintaining overall system security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a root of trust as an intermediary element within the flash memory device that mediates security operations. The root of trust provides a secure foundation for cryptographic operations, enabling the flash memory to meet high security requirements while maintaining manageable complexity through structured organization

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20220078035A1Generating an identity for a computing device using a physical unclonable function
Publication Date: 2022.03.10 MICRON TECHNOLOGY INC
  • US20220078035A1 patent drawing
  • US20220078035A1 patent drawing
  • US20220078035A1 patent drawing

AI summary

Generating, by a computing device, a device secret, the generating comprising: providing, by at least one physical unclonable function (PUF), at least one value; and generating, using a key derivative function (KDF), the device secret, wherein the at least one value provided by the at least one PUF is an input to the KDF; and storing, in memory of the computing device, the generated device secret.