Non-Volatile Storage Usage ID Generation for Per-Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing non-volatile storage devices lack effective security measures to distinguish between different content applications, leading to compromised security if the device ID is misused, potentially breaching the entire system.

Innovation Solution

A method and apparatus that generate and utilize a usage ID for each content application, based on device and application identification information, to apply security on a per-application basis, ensuring that even if the device ID is compromised, the security system can still function for specific content applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a single device ID is used for multiple content applications in a storage device, then the storage device can store diverse content types, but the security of the entire system is compromised if the device ID is misused

Engineering Contradiction:
Improvecontent application diversityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the security system by creating separate usage IDs for different content applications. Instead of using a single device ID for all applications, the system generates distinct usage IDs (e.g., first usage ID for video content, second usage ID for audio content) that are bound to specific applications. This segmentation ensures that compromise of one application's security does not affect other applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by making security properties application-specific. Each content application receives tailored security treatment through its dedicated usage ID, allowing different security policies and authentication mechanisms for different applications. The host device can enforce application-specific security rules while maintaining overall system security.

Inventive Principle:
Principle #3Local quality

2Ease of operation

If device authentication is implemented using a single device ID, then authentication is simplified, but inappropriate usage of the device ID can lead to discarding of the entire storage device

Engineering Contradiction:
Improveauthentication simplicityVSAvoidstorage device security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the authentication mechanism into application-specific segments. Instead of a single authentication check for all content, the system performs separate authentication using application-specific usage IDs. The host device authenticates each content application independently, allowing granular control over access rights and reducing the impact of authentication failures.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the authentication parameter from a static device ID to dynamic usage IDs that are specific to each content application. This parameter change allows the system to maintain authentication simplicity while enhancing security, as each usage ID can be independently managed and revoked without affecting other applications.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If content protection is applied using a single device ID, then the protection mechanism is straightforward, but security cannot be applied on a per-application basis

Engineering Contradiction:
Improveprotection mechanism complexityVSAvoidper-application security
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent segments the content protection mechanism by creating separate protection layers for different content applications. Each content type (video, audio, images) has its own usage ID and protection scheme. The host device manages multiple protection instances simultaneously, allowing flexible security policies for each application while maintaining a unified protection framework.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2732399B1Method and apparatus for using non-volatile storage device
Publication Date: 2020.02.19 SAMSUNG ELECTRONICS CO LTD
  • EP2732399B1 patent drawingFigure 1~3
  • EP2732399B1 patent drawingFigure 4
  • EP2732399B1 patent drawingFigure 5~6

AI summary

A method and apparatus for using a non-volatile storage device includes reading device identification information from the non-volatile storage device, application identification information corresponding to a content application related to a type of content to be protected or utilized among a plurality of content applications is acquired, usage identification information is generated using the device identification information and the application identification information, and protecting or utilizing content using the usage identification information.