Memory Controller Biometric Key Management for Secure Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a need for storage devices that can securely store data by encrypting and decrypting user data based on biometric information, especially in scenarios where the device may be reused or stolen, to prevent unauthorized access and data leakage.
Innovation Solution
A memory controller is designed to control access to a secure key using biometric authentication messages and unique values, encrypting and decrypting data stored in a non-volatile memory device, and managing user authentication based on biometric information provided by a biometric module.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data is stored in a non-volatile memory device without encryption, then ease of operation and access speed are improved, but data security and reliability deteriorate when the device is reused or stolen
Solution Approach 1:
The patent applies preliminary action by encrypting data before storage in the non-volatile memory device. The encryption process is performed in advance during the data writing operation, so that when data is retrieved, it is already in a secure encrypted state. This resolves the contradiction by maintaining fast access speeds while ensuring data security through pre-encryption, eliminating the need for decryption during read operations.
Solution Approach 2:
The patent introduces an intermediary encryption layer between the host system and the stored data. This encryption mechanism acts as a mediator that protects data security without affecting the ease of operation, as the encryption/decryption processes are transparent to the user and automatically managed by the storage device controller.
2Reliability
If biometric authentication and encryption mechanisms are added to the storage device, then data security is improved, but device complexity increases
Solution Approach 1:
The patent merges the biometric authentication module, encryption engine, and storage device into a single integrated system. The controller unit combines multiple functions (authentication, key management, encryption/decryption) into one component, reducing overall system complexity while maintaining high data security. This consolidation allows the device to provide advanced security features without proportionally increasing complexity.
Solution Approach 2:
The storage device controller is designed with multi-functionality, serving as both the authentication manager and encryption engine. This universal component handles multiple security-related tasks (biometric verification, key generation, data encryption) within a single device, avoiding the need for separate dedicated hardware for each function and thereby controlling complexity while enhancing security.
3Reliability
If a secure key is encrypted and stored in the memory device, then access control and data security are improved, but the time required for key authentication increases
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing encrypted versions of the secure key in the memory device during manufacturing or initial setup. When authentication is required, the system performs a rapid comparison between the provided biometric data and the pre-stored encrypted key, significantly reducing authentication time while maintaining strict access control and security.
Data Source
AI summary
A memory controller for controlling a non-volatile memory device includes a key management unit configured to control an access right to a secure key based on a biometric authentication message and a unique value, which are received from an external device; and a data processing unit configured to encrypt data received from a host and decrypt data stored in the non-volatile memory device based on the secure key.


