RPMB Sub-system Separation for Replay Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage systems with replay protected memory block (RPMB) sub-systems lack effective separation, making them vulnerable to attacks and compromising security performance.

Innovation Solution

A storage system with separated RPMB sub-systems, where a host processor and a secure element have distinct memory areas and keys/ counters, allowing independent execution of RPMB functions to enhance security by preventing replay attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a unified RPMB sub-system is used for both host processor and secure element, then device complexity is reduced, but security performance deteriorates due to vulnerability to replay attacks

Engineering Contradiction:
ImproveRPMB sub-system structureVSAvoidsecurity performance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the unified RPMB sub-system into separate first and second RPMB sub-systems. The first RPMB sub-system is dedicated to the host processor with its own keys and counters, while the second RPMB sub-system is dedicated to the secure element with separate keys and counters. This segmentation prevents cross-contamination of security contexts and blocks replay attack vectors between the host and secure element.

Inventive Principle:
Principle #1Segmentation

2Reliability

If separate RPMB sub-systems are implemented for host processor and secure element, then security performance improves, but device complexity increases

Engineering Contradiction:
Improvesecurity performanceVSAvoidRPMB sub-system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage device maintains a universal interface and control mechanism that can serve both the first RPMB sub-system for the host processor and the second RPMB sub-system for the secure element. The same storage medium and communication protocols are used, but with differentiated access control and separate key management, allowing one system to fulfill multiple security functions without proportionally increasing physical complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11550906B2Storage system with separated RPMB sub-systems and method of operating the same
Publication Date: 2023.01.10 SAMSUNG ELECTRONICS CO LTD
  • US11550906B2 patent drawing
  • US11550906B2 patent drawing
  • US11550906B2 patent drawing

AI summary

A storage system includes a host device including a host processor and a secure element distinguished from the host processor, and a storage device that includes a first memory area accessed by the host processor, and a second memory area distinguished from the first memory area and accessed by the secure element. The host processor includes a first replay protected memory block (RPMB) key and a first RPMB counter for a first RPMB subsystem of the host processor. The secure element includes a second RPMB key and a second RPMB counter for a second RPMB subsystem of secure element. The first memory area includes a third RPMB key, a third RPMB counter and a first data space of the first RPMB sub-system. The second memory area includes a fourth RPMB key, a fourth RPMB counter and a second data space of the second RPMB sub-system.