Networked Memory Device Control With Centralized Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securing cryptographic keys and managing the transfer of privileges for memory devices, leading to potential security risks and inefficiencies in controlling access and operations.
Innovation Solution
A server system comprising a key management server and an access control server is implemented to secure cryptographic keys and manage access, using cryptographic techniques to authenticate memory devices and control operations, with the access control server acting as a gatekeeper to protect the key management server from denial-of-service attacks and accommodate various memory devices and client preferences.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are secured and privilege transfer is managed through existing systems, then security is maintained, but the system complexity increases and operational efficiency decreases
Solution Approach 1:
The patent introduces a server system as an intermediary between memory devices and clients. The server includes a key management component that securely stores cryptographic keys and a privilege management component that controls access. This intermediary handles key distribution and privilege transfer, reducing the complexity burden on individual memory devices while maintaining strong security through centralized management.
2Reliability
If cryptographic techniques are used to authenticate memory devices, then security is enhanced, but the operational overhead and processing time increase
Solution Approach 1:
The patent implements preliminary action by pre-registering memory devices with the server system before actual operations. During manufacturing or initialization, memory devices are authenticated and registered with the key management server, establishing their identities and associated cryptographic keys in advance. This preliminary registration reduces authentication overhead during operational phases, as the server already has verified device identities stored for quick verification.
3Reliability
If access control is implemented for memory devices, then unauthorized access is prevented, but the ease of operation decreases
Solution Approach 1:
The patent implements self-service through automated privilege management. When a client needs access to a memory device, the privilege management component automatically verifies the client's credentials against registered devices, retrieves appropriate cryptographic keys, and grants access without manual intervention. This automation maintains strong access control while preserving ease of operation for authorized users.
4Reliability
If cryptographic keys are managed locally in memory devices, then security is improved, but key management and privilege transfer become more difficult
Solution Approach 1:
The patent introduces a server system as an intermediary between memory devices and clients. The server includes a key management component that securely stores cryptographic keys and a privilege management component that controls access. This intermediary handles key distribution and privilege transfer, reducing the complexity burden on individual memory devices while maintaining strong security through centralized management.
Data Source
AI summary
A system, method and apparatus to control memory devices over computer networks. For example, the system includes a first computer system and a second computer system. The second computer system manages cryptographic key; and the first computer system controls access to the second computer system. After establishing a secure authenticated connection between the first computer system and a client computer system, the client computer system may submit a request about a memory device. If the first computer system determines that the client computer system is eligible to operate or control the memory device, the first computer system communicate with the second computer system to generate a response to the request using at least a cryptographic key stored in the second computer system in association with an unique identification of the memory device, without the cryptographic key being transmitted to outside of the second computer system.


