Non-Volatile Memory Controller Bypassing NVMe Layers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for accessing memory storage devices by a host result in significant latency due to multiple communication layers, which hinder data fetch and execution cycles, and lack effective security measures against potential security violations in direct access modes.

Innovation Solution

The implementation of a non-volatile memory device with a controller that enables direct access to the memory through driverless commands, bypassing NVMe layers, and incorporates an anomaly detector module to monitor and respond to threshold behavior patterns, thereby reducing latency and detecting potential security violations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of time

If direct access to non-volatile memory is implemented by bypassing NVMe layers, then latency is reduced and access speed is improved, but security vulnerabilities increase due to lack of protocol-level security checks

Engineering Contradiction:
ImprovelatencyVSAvoidsecurity
Core Design Contradiction:
Loss of timeVSReliability

Solution Approach 1:

The patent introduces an intermediary security verification mechanism that operates between the host and non-volatile memory device. This intermediary layer validates access requests without requiring full NVMe protocol processing, thus maintaining reduced latency while adding security checks. The intermediary verifies access authority and monitors behavior patterns to prevent security violations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary security verification before direct memory access is granted. Access authority is verified in advance, and behavior thresholds are pre-established to detect potential security violations. This preliminary action ensures that security checks are performed before the direct access pathway is activated, preventing unauthorized operations while maintaining fast access for legitimate operations.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If multiple communication layers (host interface protocol layer, NVMe layer) are used for memory access, then security and protocol compliance are maintained, but significant latency is introduced to data fetch and execution cycles

Engineering Contradiction:
ImprovesecurityVSAvoidlatency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent extracts the essential security verification functions from the complex NVMe protocol stack. Instead of processing requests through multiple layers, only the critical security verification steps are retained and simplified. This extraction removes unnecessary protocol overhead while preserving essential security checks, achieving a balance between security and performance.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the access verification process into distinct stages: initial access authority verification, real-time behavior monitoring, and threshold-based anomaly detection. This segmentation allows security checks to be performed in discrete, efficient steps rather than as a monolithic multi-layer process, reducing overall latency while maintaining comprehensive security.

Inventive Principle:
Principle #1Segmentation

3Productivity

If direct access mode is enabled for faster data access, then productivity and data fetch speed are improved, but the system becomes more susceptible to security violations and suspicious access patterns

Engineering Contradiction:
Improvedata fetch speedVSAvoidsecurity violations
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a feedback mechanism through behavior threshold monitoring that continuously observes access patterns and provides feedback when suspicious activity is detected. When access patterns exceed predefined thresholds, the system responds by blocking or alerting on the suspicious operations. This feedback loop enables fast direct access for normal operations while automatically detecting and preventing security violations.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent applies preliminary anti-action by establishing behavior thresholds and monitoring mechanisms that proactively identify and counteract potential security violations before they can cause harm. The system pre-defines acceptable access patterns and automatically responds to deviations, preventing malicious activities while allowing legitimate fast access operations to proceed uninterrupted.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11354454B2Apparatus and method of detecting potential security violations of direct access non-volatile memory device
Publication Date: 2022.06.07 SANDISK TECHNOLOGIES LLC
  • US11354454B2 patent drawing
  • US11354454B2 patent drawing
  • US11354454B2 patent drawing

AI summary

An apparatus and method of providing direct access to a non-volatile memory of a non-volatile memory device and detecting potential security violations are provided. A method for providing access to a non-volatile memory of a non-volatile memory device may include tracking a parameter related to a plurality of direct access transactions of the non-volatile memory. A threshold behavior pattern of the host activity may be determined based upon the tracked parameters. The direct access transactions may be reviewed to determine whether the threshold behavior pattern is exceeded.