Secure Memory Device Identity Validation via Internal Cryptographic Engine
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current authentication methods for communication endpoints with secure memory devices in networks lack robustness against tampering, hacking, and unauthorized access, as they rely on external processors for security computations and do not effectively verify the integrity and authenticity of data stored in memory devices.
Innovation Solution
Implementing a security server and memory devices with integrated security features, such as a cryptographic engine and access controller, that perform cryptographic computations locally within the memory device, using a unique device secret and additional data to generate cryptographic keys, and validate the identity and integrity of the device through cryptographic computations, ensuring secure communication and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If external processors are used for security computations, then device complexity is reduced, but security reliability deteriorates due to vulnerability to tampering and hacking
Solution Approach 1:
The patent extracts the security computation functionality from external processors and places it directly within the memory device. The memory device now includes an integrated cryptographic engine and access controller that perform security computations internally, using a unique device secret stored in secure memory to generate cryptographic keys and authenticate access requests, thereby eliminating reliance on external processors for critical security operations
Solution Approach 2:
The patent implements a nested structure where the cryptographic engine and access controller are embedded within the memory device architecture. The unique device secret is stored in secure memory within the memory device, and the cryptographic engine uses this secret to generate keys that are then used by the access controller to authenticate external processors, creating a layered security implementation where security functions are nested within the memory device itself
2Ease of manufacture
If cryptographic keys are stored externally, then manufacturing simplicity is maintained, but security against unauthorized access deteriorates
Solution Approach 1:
The patent extracts the unique device secret from external storage and embeds it directly within the memory device in a secure memory location that is inaccessible to external processors. This extraction and internalization of the secret key prevents unauthorized access and tampering while maintaining manufacturing simplicity through integrated fabrication processes
Solution Approach 2:
The patent creates a composite security architecture combining multiple elements within the memory device: secure memory for storing the unique device secret, a cryptographic engine for key generation, and an access controller for authentication. This composite structure integrates different functional components into a unified secure system that resists unauthorized access while being manufacturable as a single device
3Productivity
If data integrity verification is not implemented, then processing speed is improved, but data authenticity deteriorates
Solution Approach 1:
The patent implements preliminary action by pre-storing a hash value of the unique device secret in secure memory within the memory device during manufacturing. This pre-computed hash serves as a reference for later integrity verification, allowing the system to quickly authenticate data authenticity by comparing received data against this pre-stored hash without requiring complex real-time verification computations
Data Source
AI summary
A security server to validate identity data of computing devices having secure memory devices and track activities of components in the computing devices. The server system is configured to store data representative of a unique device secret sealed in the memory device. The server system can generate a first cryptographic key independently from the memory device generating a second cryptographic key. The memory device uses the second cryptographic key to generate identity data including a message and a verification code generated via cryptographic operations combining the message and the second cryptographic key. The server system can use the first cryptographic key to determine whether the verification code is valid for the message. If so, the security server can generate an activity record associating the activity of the computing device with identifications of respective components of the computing device confirmed via validation of the identity data.


