Memory Device Access Control via Isolated Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory device security systems face challenges in securing cryptographic keys and ensuring secure transfer of privileges, leading to potential security risks and vulnerabilities.
Innovation Solution
A server system comprising a key management server and an access control server is implemented to manage cryptographic keys and control access, using cryptographic techniques to authenticate memory devices and ensure secure operations, with the access control server acting as a gatekeeper to protect the key management server from denial-of-service attacks and accommodate various memory devices and client preferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are stored in the key management server to enable secure operations, then security is improved, but the system becomes more vulnerable to denial-of-service attacks and unauthorized access
Solution Approach 1:
The access control server acts as an intermediary between client systems and the key management server. It receives access requests, validates them against stored access control data, and only forwards legitimate requests to the key management server. This mediator architecture protects the key management server from direct exposure to potential denial-of-service attacks while maintaining secure cryptographic key management functionality.
2Adaptability or versatility
If the key management server handles all access control operations directly, then the system is simpler, but it cannot accommodate various client preferences and memory device types
Solution Approach 1:
The system divides functionality into two separate servers: the key management server that stores cryptographic keys and provides core security functions, and the access control server that handles diverse access control operations for different clients and memory devices. This segmentation allows each component to be optimized for its specific function while maintaining overall system versatility without excessive complexity.
3Ease of operation
If access control data is stored centrally to enable unified management, then control is improved, but security risks increase
Solution Approach 1:
The access control server serves as a controlled intermediary that manages access control data centrally for unified control purposes, but it validates all requests against this data before allowing access to the key management server. This intermediary architecture enables centralized management convenience while maintaining security through validation layers that prevent unauthorized access even if the access control data is compromised.
Data Source
AI summary
A system, method and apparatus to control memory devices over computer networks. For example, the system includes a first computer system and a second computer system. The second computer system manages cryptographic key; and the first computer system controls access to the second computer system. After establishing a secure authenticated connection between the first computer system and a client computer system, the client computer system may submit a request about a memory device. If the first computer system determines that that the client computer system is eligible to operate or control the memory device, the first computer system communicate with the second computer system to generate a response to the request using at least a cryptographic key stored in the second computer system in association with an unique identification of the memory device, without the cryptographic key being transmitted to outside of the second computer system.


