Memory Controller Authentication for Secure System Information

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory systems lack effective mechanisms to prevent the indiscriminate leakage of sensitive system information, particularly in nonvolatile memory devices used in various electronic devices.

Innovation Solution

A memory system incorporating a nonvolatile memory device and a controller that receives system information requests from host devices, determines suitability based on shared security information, and encrypts the information using fixed and variable keys before transmission, ensuring secure data exchange.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If system information is transmitted without encryption, then transmission speed and simplicity are improved, but security and confidentiality deteriorate

Engineering Contradiction:
Improvetransmission speedVSAvoidinformation leakage
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent applies parameter changes by switching between encrypted and unencrypted transmission modes based on authentication results. The controller changes the transmission parameter (encryption state) from unencrypted (fast) to encrypted (secure) after successful authentication, resolving the contradiction between transmission speed and security.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements preliminary action by performing authentication and establishing encryption keys before transmitting sensitive system information. The controller pre-configures the secure transmission channel through authentication procedures, ensuring security is in place before data exchange occurs.

Inventive Principle:
Principle #10Preliminary action

2Object-affected harmful factors

If authentication mechanisms are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized accessVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the system into two parts: a master device that stores authentication information and a slave device that verifies it. This segmentation allows the slave device to maintain simplicity while still implementing security through the master-slave relationship and shared secret mechanism.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent uses an intermediary approach by introducing a shared secret (first information) as a mediator between master and slave devices. This intermediary element enables mutual authentication without requiring complex cryptographic protocols in the slave device, balancing security with simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If encryption is applied to all data transmission, then security is improved, but processing overhead and energy consumption increase

Engineering Contradiction:
Improvedata leakageVSAvoidenergy consumption
Core Design Contradiction:
Object-affected harmful factorsVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by encrypting only the authentication information and critical system parameters rather than all data transmissions. The controller selectively applies encryption to the minimum necessary data (authentication tokens, system information requests), reducing processing overhead while maintaining security for sensitive operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11550929B2Memory system
Publication Date: 2023.01.10 SK HYNIX INC
  • US11550929B2 patent drawing
  • US11550929B2 patent drawing
  • US11550929B2 patent drawing

AI summary

A memory system includes a nonvolatile memory device; and a controller configured to control the nonvolatile memory device, wherein the controller is configured to: receive a system information request including a command and an argument from a host device; determine suitability of the system information request based on a fixed key included in the argument in response to the command; encrypt system information based the argument when the system information request is suitable; and transmit the encrypted system information to the host device.