Identity Object Authentication for Secure Flash Memory Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory systems lack secure and efficient methods for authenticating and managing access to encrypted data on removable storage devices, such as flash memory cards, which hinders secure distribution and protection of digital content.

Innovation Solution

The implementation of an identity object with a public key and private key pair, certified by a certificate authority, is used to authenticate and encrypt data on a memory system, allowing secure access and decryption of encrypted data by authorized entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods are used in memory systems, then the system structure remains simple, but security and reliability are insufficient for protecting encrypted data

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an identity object as an intermediary component that mediates between the host device and the memory system. This identity object contains cryptographic key pairs and certificates, serving as a security intermediary that enables reliable authentication without requiring complex custom authentication circuits in the memory device itself. The identity object can be stored in the memory device or on a removable card, providing flexibility while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If identity objects with cryptographic key pairs are implemented, then authentication security is improved, but the device complexity and storage requirements increase

Engineering Contradiction:
Improveaccess control securityVSAvoidmemory storage
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts the cryptographic identity objects (public keys, private keys, and certificates) from the core memory system and stores them separately, either in a dedicated security area of the memory device or on a removable memory card. This extraction allows the main memory storage to be used for data while the identity objects occupy minimal dedicated space. The private key remains secured in the memory device while the public key and certificates can be freely exchanged.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If public key infrastructure is used for authentication, then data protection is enhanced, but the ease of operation and key management becomes more difficult

Engineering Contradiction:
Improvedata encryption securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the memory system automatically performs cryptographic operations using the stored identity objects. When a host device needs to access encrypted data, the memory system automatically uses the private key to verify the host's credentials and decrypt data without requiring manual key input or complex key management procedures from the user. The system autonomously handles key selection, encryption, and decryption operations.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If removable memory devices are used for content distribution, then versatility and portability are improved, but security control across different host devices becomes more challenging

Engineering Contradiction:
Improvehost device compatibilityVSAvoidcross-device security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a universal authentication mechanism using standardized public key infrastructure that enables the memory device to work securely with multiple different host devices. The identity object contains certificates that can be verified by any host device equipped with the corresponding root certificate authority's public key. This universal approach allows the same memory device to be used across different computers, media players, and other host devices while maintaining security through cryptographic verification rather than device-specific authentication.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8639939B2Control method using identity objects
Publication Date: 2014.01.28 SANDISK TECHNOLOGIES LLC
  • US8639939B2 patent drawing
  • US8639939B2 patent drawing
  • US8639939B2 patent drawing

AI summary

An object known as an identity object comprises a public key and a private key pair and at least one certificate issued by a certificate authority that certifies that the public key of the pair is genuine. In one embodiment, this object may be used as proof of identification by using the private key to sign data provided to it or signals derived from the data. An identity object may be stored in a non-volatile memory as proof of identity, where the memory is controlled by a controller. Preferably, a housing encloses the memory and the controller.