Non-Volatile Storage Usage ID Generation for Per-Application Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing non-volatile storage devices lack effective security measures to distinguish between different content applications, leading to compromised security if the device ID is misused, potentially breaching the entire system.
Innovation Solution
A method and apparatus that generate and utilize a usage ID for each content application, based on device and application identification information, to apply security on a per-application basis, ensuring that even if the device ID is compromised, the security system can still function for specific content applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a single device ID is used for multiple content applications in a storage device, then the storage device can store diverse content types, but the security of the entire system is compromised if the device ID is misused
Solution Approach 1:
The patent segments the security system by creating separate usage IDs for different content applications. Instead of using a single device ID for all applications, the system generates distinct usage IDs (e.g., first usage ID for video content, second usage ID for audio content) that are bound to specific applications. This segmentation ensures that compromise of one application's security does not affect other applications.
Solution Approach 2:
The patent applies local quality by making security properties application-specific. Each content application receives tailored security treatment through its dedicated usage ID, allowing different security policies and authentication mechanisms for different applications. The host device can enforce application-specific security rules while maintaining overall system security.
2Ease of operation
If device authentication is implemented using a single device ID, then authentication is simplified, but inappropriate usage of the device ID can lead to discarding of the entire storage device
Solution Approach 1:
The patent divides the authentication mechanism into application-specific segments. Instead of a single authentication check for all content, the system performs separate authentication using application-specific usage IDs. The host device authenticates each content application independently, allowing granular control over access rights and reducing the impact of authentication failures.
Solution Approach 2:
The patent changes the authentication parameter from a static device ID to dynamic usage IDs that are specific to each content application. This parameter change allows the system to maintain authentication simplicity while enhancing security, as each usage ID can be independently managed and revoked without affecting other applications.
3Device complexity
If content protection is applied using a single device ID, then the protection mechanism is straightforward, but security cannot be applied on a per-application basis
Solution Approach 1:
The patent segments the content protection mechanism by creating separate protection layers for different content applications. Each content type (video, audio, images) has its own usage ID and protection scheme. The host device manages multiple protection instances simultaneously, allowing flexible security policies for each application while maintaining a unified protection framework.
Data Source
Figure 1~3
Figure 4
Figure 5~6
AI summary
A method and apparatus for using a non-volatile storage device includes reading device identification information from the non-volatile storage device, application identification information corresponding to a content application related to a type of content to be protected or utilized among a plurality of content applications is acquired, usage identification information is generated using the device identification information and the application identification information, and protecting or utilizing content using the usage identification information.