RPMB Security Data Sharing via Encrypted Key Exchange

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current electronic devices lack secure methods for sharing and updating security data stored in replay protected memory blocks (RPMB) with external devices, risking unauthorized access and data leakage.

Innovation Solution

An electronic device with a memory device containing a replay protected memory block (RPMB) and a memory controller that verifies external devices using a password or one-time password (OTP), encrypts security data, and transmits it along with a decryption key and RPMB key to authorized external devices for secure access and updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security data is stored in RPMB for secure access, then data security is improved, but the ability to share and update security data with external devices deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiddata sharing capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security data management system is segmented into multiple components: RPMB for secure storage, memory controller for verification and key management, and host device for encryption and data processing. This segmentation allows each component to perform its specialized function while maintaining overall security and enabling controlled sharing with external devices.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The memory controller acts as an intermediary between the RPMB and external devices. It verifies external devices using passwords or OTP, manages decryption keys, and controls access to security data. This intermediary role enables secure data sharing while maintaining the security guarantees of RPMB storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security data is encrypted and accessed only through verification, then unauthorized access is prevented, but data access and updating operations become more complex

Engineering Contradiction:
Improveaccess control securityVSAvoiddata access operation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

External devices are verified in advance using passwords or one-time passwords (OTP) before any security data operations. Decryption keys are pre-established and managed by the memory controller. These preliminary actions ensure that only authenticated devices can access or update security data, simplifying subsequent operations while maintaining strong security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-verification through automated password and OTP checking by the memory controller. The host device automatically encrypts security data before storage. These automated self-service mechanisms reduce manual intervention complexity while maintaining rigorous access control.

Inventive Principle:
Principle #25Self-service

3Reliability

If security data is updated in RPMB, then data currency is improved, but maintaining security and synchronization across devices becomes more difficult

Engineering Contradiction:
Improvedata currencyVSAvoiddata synchronization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses feedback mechanisms where the memory controller verifies external devices and manages key distribution before allowing updates. The host device encrypts updated security data before writing to RPMB. This feedback loop ensures data currency is maintained while security and synchronization are automatically managed, reducing manual coordination complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The memory controller performs multiple functions: verifying external devices, managing decryption keys, controlling RPMB access, and coordinating updates. The host device handles both encryption and update operations. This multi-functionality consolidates synchronization complexity into centralized components, enabling data currency improvements without proportionally increasing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12197746B2Electronic device and method of operating the same
Publication Date: 2025.01.14 SK HYNIX INC
  • US12197746B2 patent drawing
  • US12197746B2 patent drawing
  • US12197746B2 patent drawing

AI summary

Provided herein may be an electronic device and a method of operating the same. The electronic device may include a memory device including a replay protected memory block (RPMB) configured to store security data, a memory controller configured to control the memory device, and a host device configured to verify, using a password, an external device coupled thereto wherein the memory controller controls the memory device to read, when the external device is verified, the security data, and wherein the host device is further configured to encrypt the read security data, and transmit, to the verified external device, the encrypted security data, a decryption key for decrypting the encrypted security data, and an RPMB key for accessing the security data.