Memory Controller Access Control for Non-Volatile Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In non-volatile memory devices, ensuring secure access control among multiple sub-systems that share access to the memory is challenging, particularly when these sub-systems do not trust each other, as existing solutions lack effective mechanisms to enforce access rights based on entity identifiers.
Innovation Solution
A memory controller is implemented to manage access to non-volatile memory by verifying identifiers in memory access messages and granting or denying access based on predefined access rights, with the option to embed the memory controller and non-volatile memory within a casing or semiconductor package for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple sub-systems share access to non-volatile memory without trust relationships, then memory accessibility is improved, but data security deteriorates
Solution Approach 1:
The patent introduces a memory controller as an intermediary between multiple sub-systems and the non-volatile memory. The memory controller verifies entity identifiers and enforces access rights, acting as a trusted mediator that enables multiple sub-systems to access memory securely without requiring mutual trust between them. This resolves the contradiction by maintaining data security while allowing broad accessibility.
Solution Approach 2:
The patent segments the memory access control by dividing memory into different regions and assigning specific access rights to different entities. The memory controller checks entity identifiers and grants access only to authorized regions, allowing multiple sub-systems to share memory resources while maintaining security boundaries. This enables versatility in access while preserving data security through regional segmentation.
2Reliability
If access control mechanisms are implemented to prevent unauthorized access, then data security is improved, but device complexity increases
Solution Approach 1:
The memory controller performs self-service by automatically verifying entity identifiers and enforcing access rights without requiring external intervention. The system embeds the access control logic within the memory controller itself, allowing it to autonomously manage security. This reduces overall system complexity by consolidating security functions into a single self-managing component rather than requiring complex external control mechanisms.
Solution Approach 2:
The patent merges the access control functionality with the memory controller, combining security verification with memory management in a single integrated component. By merging these functions, the system avoids the complexity of separate security subsystems while maintaining robust data protection. The memory controller simultaneously handles both memory operations and security enforcement, reducing device complexity.
3Measurement precision
If memory controller verifies entity identifiers for each access request, then access control precision is improved, but processing speed decreases
Solution Approach 1:
The system performs preliminary action by pre-establishing access rights and entity identifiers before memory access operations. The memory controller has pre-configured authorization information that allows it to quickly verify access requests without complex real-time computations. This preliminary preparation maintains high access control precision while minimizing processing overhead and preserving memory access speed.
Data Source
AI summary
Technology is disclosed that provides security for data stored in a non-volatile memory device. The non-volatile memory device may be embedded in a host system. The host system may further have a host controller that is configured to obtain a memory access message from an initiator to access the non-volatile memory. The host controller may be further configured to provide the memory access message to the memory controller. The memory access message may contain an identifier of the initiator, which may be verified by the host controller. The memory controller may be configured to access the identifier of the initiator from the memory access message, and grant or deny non-volatile memory access to the initiator based on whether the initiator has access rights to a region of the non-volatile memory to which the initiator seeks access.


