Memory Controller Access Control for Non-Volatile Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In non-volatile memory devices, ensuring secure access control among multiple sub-systems that share access to the memory is challenging, particularly when these sub-systems do not trust each other, as existing solutions lack effective mechanisms to enforce access rights based on entity identifiers.

Innovation Solution

A memory controller is implemented to manage access to non-volatile memory by verifying identifiers in memory access messages and granting or denying access based on predefined access rights, with the option to embed the memory controller and non-volatile memory within a casing or semiconductor package for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple sub-systems share access to non-volatile memory without trust relationships, then memory accessibility is improved, but data security deteriorates

Engineering Contradiction:
Improvememory accessibilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a memory controller as an intermediary between multiple sub-systems and the non-volatile memory. The memory controller verifies entity identifiers and enforces access rights, acting as a trusted mediator that enables multiple sub-systems to access memory securely without requiring mutual trust between them. This resolves the contradiction by maintaining data security while allowing broad accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the memory access control by dividing memory into different regions and assigning specific access rights to different entities. The memory controller checks entity identifiers and grants access only to authorized regions, allowing multiple sub-systems to share memory resources while maintaining security boundaries. This enables versatility in access while preserving data security through regional segmentation.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access control mechanisms are implemented to prevent unauthorized access, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidaccess control mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The memory controller performs self-service by automatically verifying entity identifiers and enforcing access rights without requiring external intervention. The system embeds the access control logic within the memory controller itself, allowing it to autonomously manage security. This reduces overall system complexity by consolidating security functions into a single self-managing component rather than requiring complex external control mechanisms.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges the access control functionality with the memory controller, combining security verification with memory management in a single integrated component. By merging these functions, the system avoids the complexity of separate security subsystems while maintaining robust data protection. The memory controller simultaneously handles both memory operations and security enforcement, reducing device complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If memory controller verifies entity identifiers for each access request, then access control precision is improved, but processing speed decreases

Engineering Contradiction:
Improveaccess control precisionVSAvoidmemory access speed
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The system performs preliminary action by pre-establishing access rights and entity identifiers before memory access operations. The memory controller has pre-configured authorization information that allows it to quickly verify access requests without complex real-time computations. This preliminary preparation maintains high access control precision while minimizing processing overhead and preserving memory access speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10712976B2Storage protection unit
Publication Date: 2020.07.14 SANDISK TECHNOLOGIES LLC
  • US10712976B2 patent drawing
  • US10712976B2 patent drawing
  • US10712976B2 patent drawing

AI summary

Technology is disclosed that provides security for data stored in a non-volatile memory device. The non-volatile memory device may be embedded in a host system. The host system may further have a host controller that is configured to obtain a memory access message from an initiator to access the non-volatile memory. The host controller may be further configured to provide the memory access message to the memory controller. The memory access message may contain an identifier of the initiator, which may be verified by the host controller. The memory controller may be configured to access the identifier of the initiator from the memory access message, and grant or deny non-volatile memory access to the initiator based on whether the initiator has access rights to a region of the non-volatile memory to which the initiator seeks access.