Nonvolatile Memory Module Authentication Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional nonvolatile memory devices face security issues due to the risk of data integrity and access speed, particularly when used in computing systems, as they can be vulnerable to hacking and duplication, and existing certification methods are inadequate in ensuring secure access.

Innovation Solution

A nonvolatile memory module that generates a certification value based on device identifiers of authorized user systems, using an authentication engine to control access and encrypt data, thereby preventing unauthorized access and ensuring secure data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If nonvolatile memory is used to retain data at power-off, then data persistence is improved, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvedata retention timeVSAvoidunauthorized access risk
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by generating a certification value based on device identifiers before any data access occurs. The authentication engine creates this certification value during initialization and stores it in the nonvolatile memory, so that when access is attempted, the system already has the necessary authentication data ready to compare against incoming access requests. This prevents unauthorized access while maintaining data persistence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism between the stored data and any access attempts. The certification value, derived from device identifiers through cryptographic functions, acts as an intermediary that must be validated before data can be accessed. This intermediary layer ensures that even though data persists in nonvolatile memory, it remains protected from unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If conventional certification methods (password, certificate) are used, then ease of operation is improved, but security against hacking and duplication deteriorates

Engineering Contradiction:
Improveaccess convenienceVSAvoidsecurity against hacking
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements self-service by having the system automatically generate and verify certification values without requiring manual password input or certificate management from the user. The authentication engine autonomously creates the certification value based on device identifiers and automatically compares it with access requests, eliminating the need for users to manually manage passwords or certificates while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces conventional mechanical certification methods (physical passwords, certificates) with a cryptographic system based on device identifiers. Instead of relying on user-managed credentials that can be hacked or duplicated, the system uses hardware-bound device identifiers processed through cryptographic functions to generate certification values, providing more reliable security while maintaining ease of operation.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If device certification is implemented, then security against software hacking is improved, but vulnerability to device duplication deteriorates

Engineering Contradiction:
Improveprotection against software hackingVSAvoiddevice duplication risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent uses a composite authentication approach by combining multiple device identifiers from different devices in the system to generate the certification value. Rather than relying on a single device identifier that could be duplicated, the system composite together identifiers from multiple sources (e.g., host device, storage device, processing device) through cryptographic functions. This composite approach ensures that even if one device identifier is compromised, the overall certification remains secure.

Inventive Principle:
Principle #40Composite materials

4Reliability

If certification value is stored in nonvolatile memory, then access control is improved, but risk of data breach upon unauthorized access deteriorates

Engineering Contradiction:
Improveaccess control capabilityVSAvoiddata breach impact
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing an authentication check before any data access can occur. The system预先 compares the incoming access request's certification value against the stored certification value derived from device identifiers. If the comparison fails, access is blocked before any data can be read or modified. This preliminary verification prevents unauthorized access and potential data breaches before they can happen.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS9251099B2Nonvolatile memory modules and authorization systems and operating methods thereof
Publication Date: 2016.02.02 SAMSUNG ELECTRONICS CO LTD
  • US9251099B2 patent drawing
  • US9251099B2 patent drawing
  • US9251099B2 patent drawing

AI summary

Memory modules and authorization systems include a nonvolatile memory, an authentication engine configured to receive an initialization request from a user system, configured to generate a certification value based on device identifiers of devices includes in the user system in response to the initialization request and configured to control access to the nonvolatile memory based on the certification value, and a certification value storage configured to store the certification value.