RPMB Memory Controller Authentication Under Power Interruptions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage devices lack robust security features to protect sensitive data stored in nonvolatile memory blocks, particularly in scenarios where power integrity is compromised.
Innovation Solution
Incorporation of a replay protected memory block (RPMB) with a memory controller that performs authentication and secure data handling, including message authentication codes, to ensure secure storage and retrieval of data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional nonvolatile memory blocks are used for data storage, then storage capacity and accessibility are improved, but security and data integrity are compromised when power integrity is compromised
Solution Approach 1:
The memory system is divided into two distinct types of memory blocks: traditional nonvolatile memory blocks for general data storage, and replay protected memory blocks (RPMB) for secure data storage. This segmentation allows different security levels to be applied to different data, protecting critical data against power interruptions while maintaining accessibility of general data.
Solution Approach 2:
The RPMB acts as an intermediary layer between the host and the traditional nonvolatile memory. It provides authentication and security functions, verifying data integrity before allowing access to stored information, thereby protecting against power interruption attacks without compromising the functionality of the underlying storage system.
2Reliability
If authentication operations are implemented in the memory controller, then data security is improved, but device complexity increases
Solution Approach 1:
Authentication data and security parameters are pre-configured in the RPMB during manufacturing or initialization. The memory controller uses these pre-configured credentials to perform authentication operations, eliminating the need for complex real-time authentication key management and reducing controller complexity while maintaining security.
3Reliability
If replay protected memory blocks are added to the storage device, then security function is improved, but device complexity increases
Solution Approach 1:
The RPMB is integrated into the existing nonvolatile memory device structure, sharing physical resources such as memory cells, word lines, and bit lines with traditional memory blocks. This merging approach allows security functionality to be added without requiring a completely separate memory system, thereby reducing the impact on device complexity.
Data Source
AI summary
A storage device includes a nonvolatile memory device including a replay protected memory block; and a memory controller for, as a submission command requesting access to the replay protected memory block is received from an external host including a host memory having a plurality of Physical Region Pages (PRPs), acquiring a host replay protected memory block data frame stored in one of the plurality of PRPs included in the external host and accessing the replay protected memory block. The submission command may include information on a position at which the memory controller is to store a response to the submission command among the plurality of PRPs.


