Memory Controller Anti-Replay Authentication via Identity Key Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory devices face security threats due to exposure of personal information, which can lead to financial loss and safety issues, and previous anti-hacking mechanisms require additional circuitry, increasing complexity and size.

Innovation Solution

An anti-hacking mechanism that utilizes existing memory device circuitry and firmware to provide secure communication by encrypting subscriber information with an identity public key, without requiring additional components or circuitry dedicated to anti-replay functionality.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional circuitry is added to provide anti-hacking functionality, then security against replay attacks is improved, but device complexity and size increase

Engineering Contradiction:
Improvesecurity against replay attacksVSAvoidcircuitry complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the anti-hacking functionality with existing memory device circuitry by implementing a state machine within the controller that uses authentication keys stored in the memory device. This combines security functions with existing structural elements rather than adding separate dedicated circuitry, thereby improving security while avoiding increased device complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The controller is designed to perform multiple functions including normal memory operations and security authentication. The state machine mechanism is universally applicable to different authentication scenarios (read, program, erase operations) using the same structural elements, making the security system multi-functional and avoiding the need for dedicated anti-hacking circuitry.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If additional components are added for anti-replay functionality, then protection against hacking threats is improved, but manufacturing complexity increases

Engineering Contradiction:
Improveprotection against hacking threatsVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The authentication mechanism is merged into the existing memory device structure, using the controller and memory cells that are already part of the device. The state machine and authentication key storage utilize existing components, eliminating the need for additional manufacturing steps and specialized components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The memory device performs its own authentication and anti-hacking functions using internally stored authentication keys and a state machine implemented in the controller. This self-service approach eliminates the need for external security components or complex manufacturing processes for adding dedicated security hardware.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12003632B2Secure communication in accessing a network
Publication Date: 2024.06.04 MICRON TECHNOLOGY INC
  • US12003632B2 patent drawing
  • US12003632B2 patent drawing
  • US12003632B2 patent drawing

AI summary

Secure communication in accessing a network is described herein. An example apparatus can include a memory and a processor coupled to the memory. The processor can be configured to receive an identity public key from the identity device. The identity public key can be received in response to providing, to the identity device, a request to modify content of the identity device. The processor can be further configured to encrypt data corresponding to subscriber information using the identity public key, provide (to the identity device) the encrypted data to store the subscriber information in the identity device, and access a network operated by a network operator via the data stored in the identity device.