Memory Controller Biometric Key Management for Secure Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for storage devices that can securely store data by encrypting and decrypting user data based on biometric information, especially in scenarios where the device may be reused or stolen, to prevent unauthorized access and data leakage.

Innovation Solution

A memory controller is designed to control access to a secure key using biometric authentication messages and unique values, encrypting and decrypting data stored in a non-volatile memory device, and managing user authentication based on biometric information provided by a biometric module.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored in a non-volatile memory device without encryption, then ease of operation and access speed are improved, but data security and reliability deteriorate when the device is reused or stolen

Engineering Contradiction:
Improvedata access speedVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by encrypting data before storage in the non-volatile memory device. The encryption process is performed in advance during the data writing operation, so that when data is retrieved, it is already in a secure encrypted state. This resolves the contradiction by maintaining fast access speeds while ensuring data security through pre-encryption, eliminating the need for decryption during read operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary encryption layer between the host system and the stored data. This encryption mechanism acts as a mediator that protects data security without affecting the ease of operation, as the encryption/decryption processes are transparent to the user and automatically managed by the storage device controller.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If biometric authentication and encryption mechanisms are added to the storage device, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the biometric authentication module, encryption engine, and storage device into a single integrated system. The controller unit combines multiple functions (authentication, key management, encryption/decryption) into one component, reducing overall system complexity while maintaining high data security. This consolidation allows the device to provide advanced security features without proportionally increasing complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The storage device controller is designed with multi-functionality, serving as both the authentication manager and encryption engine. This universal component handles multiple security-related tasks (biometric verification, key generation, data encryption) within a single device, avoiding the need for separate dedicated hardware for each function and thereby controlling complexity while enhancing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a secure key is encrypted and stored in the memory device, then access control and data security are improved, but the time required for key authentication increases

Engineering Contradiction:
Improveaccess controlVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing encrypted versions of the secure key in the memory device during manufacturing or initial setup. When authentication is required, the system performs a rapid comparison between the provided biometric data and the pre-stored encrypted key, significantly reducing authentication time while maintaining strict access control and security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230273884A1Memory controller, storage device including the same, and operating method of the memory controller
Publication Date: 2023.08.31 SAMSUNG ELECTRONICS CO LTD
  • US20230273884A1 patent drawing
  • US20230273884A1 patent drawing
  • US20230273884A1 patent drawing

AI summary

A memory controller for controlling a non-volatile memory device includes a key management unit configured to control an access right to a secure key based on a biometric authentication message and a unique value, which are received from an external device; and a data processing unit configured to encrypt data received from a host and decrypt data stored in the non-volatile memory device based on the secure key.