Solid-State Memory Controller Security Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory device security management requires administrator privileges and a device driver specific to each type of memory device, making it cumbersome and limiting in flexibility.

Innovation Solution

A memory device with a controller that identifies and executes control commands within data blocks, authenticating them to manage access to secure memory without the need for a custom device driver or administrator privileges, allowing access to secure memory based on authenticated commands.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a device driver specific to each memory device type is installed to manage security, then security management capability is provided, but device complexity and installation requirements increase

Engineering Contradiction:
Improvesecurity management capabilityVSAvoiddevice driver requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security management approach where the memory device itself provides security functions through standardized commands that can be executed by any host operating system without requiring device-specific drivers. The controller interprets security commands and manages access control directly, making the security functionality universal across different device types and operating systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The memory device performs security management autonomously through its controller, which directly processes security commands from the host and manages access control without external driver intervention. The device self-manages authentication, authorization, and security policy enforcement, eliminating the need for host-side driver software to mediate these functions.

Inventive Principle:
Principle #25Self-service

2Reliability

If administrator privileges are required to manage memory device security, then security control is enforced, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoidoperation simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The memory device autonomously enforces security controls through its controller, which independently validates commands and manages access without requiring elevated host privileges. The device self-manages security policies, authentication credentials, and access decisions, allowing standard user accounts to interact with the device without administrator rights while maintaining robust security control.

Inventive Principle:
Principle #25Self-service

3Reliability

If custom device drivers are installed for each memory device type, then device-specific security commands are supported, but adaptability and versatility decrease

Engineering Contradiction:
Improvedevice-specific command supportVSAvoidoperating system compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal command interface where the memory device controller directly interprets security commands from the host without requiring device-specific drivers. The controller handles diverse security operations (authentication, authorization, access control) through a standardized command set that works across different operating systems and device types, enhancing adaptability while maintaining reliable security functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8850150B2Managing security in solid-state devices
Publication Date: 2014.09.30 WESTERN DIGITAL TECHNOLOGIES INC
  • US8850150B2 patent drawing
  • US8850150B2 patent drawing
  • US8850150B2 patent drawing

AI summary

A computing device and method for managing security of a memory or storage device without the need for administer privileges. To access the secure memory, a host provides a data block containing a control command and authentication data to the memory device. The memory device includes a controller for controlling access to a secure memory in the memory device. The memory device identifies the control command in the data block, authenticates the control command bused on the authentication data, and executes the control command to allow the host device to access the secure memory.