Secure Memory Device Identity Validation via Internal Cryptographic Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for communication endpoints with secure memory devices in networks lack robustness against tampering, hacking, and unauthorized access, as they rely on external processors for security computations and do not effectively verify the integrity and authenticity of data stored in memory devices.

Innovation Solution

Implementing a security server and memory devices with integrated security features, such as a cryptographic engine and access controller, that perform cryptographic computations locally within the memory device, using a unique device secret and additional data to generate cryptographic keys, and validate the identity and integrity of the device through cryptographic computations, ensuring secure communication and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If external processors are used for security computations, then device complexity is reduced, but security reliability deteriorates due to vulnerability to tampering and hacking

Engineering Contradiction:
Improvesecurity computation architectureVSAvoidsecurity authentication
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts the security computation functionality from external processors and places it directly within the memory device. The memory device now includes an integrated cryptographic engine and access controller that perform security computations internally, using a unique device secret stored in secure memory to generate cryptographic keys and authenticate access requests, thereby eliminating reliance on external processors for critical security operations

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a nested structure where the cryptographic engine and access controller are embedded within the memory device architecture. The unique device secret is stored in secure memory within the memory device, and the cryptographic engine uses this secret to generate keys that are then used by the access controller to authenticate external processors, creating a layered security implementation where security functions are nested within the memory device itself

Inventive Principle:
Principle #7Nested doll (Nesting)

2Ease of manufacture

If cryptographic keys are stored externally, then manufacturing simplicity is maintained, but security against unauthorized access deteriorates

Engineering Contradiction:
Improvedevice fabricationVSAvoidunauthorized access and tampering
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the unique device secret from external storage and embeds it directly within the memory device in a secure memory location that is inaccessible to external processors. This extraction and internalization of the secret key prevents unauthorized access and tampering while maintaining manufacturing simplicity through integrated fabrication processes

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a composite security architecture combining multiple elements within the memory device: secure memory for storing the unique device secret, a cryptographic engine for key generation, and an access controller for authentication. This composite structure integrates different functional components into a unified secure system that resists unauthorized access while being manufacturable as a single device

Inventive Principle:
Principle #40Composite materials

3Productivity

If data integrity verification is not implemented, then processing speed is improved, but data authenticity deteriorates

Engineering Contradiction:
Improvedata processing speedVSAvoiddata authenticity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary action by pre-storing a hash value of the unique device secret in secure memory within the memory device during manufacturing. This pre-computed hash serves as a reference for later integrity verification, allowing the system to quickly authenticate data authenticity by comparing received data against this pre-stored hash without requiring complex real-time verification computations

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240430253A1Track Activities of components in Endpoints having Secure Memory Devices via Identity Validation
Publication Date: 2024.12.26 MICRON TECHNOLOGY INC
  • US20240430253A1 patent drawing
  • US20240430253A1 patent drawing
  • US20240430253A1 patent drawing

AI summary

A security server to validate identity data of computing devices having secure memory devices and track activities of components in the computing devices. The server system is configured to store data representative of a unique device secret sealed in the memory device. The server system can generate a first cryptographic key independently from the memory device generating a second cryptographic key. The memory device uses the second cryptographic key to generate identity data including a message and a verification code generated via cryptographic operations combining the message and the second cryptographic key. The server system can use the first cryptographic key to determine whether the verification code is valid for the message. If so, the security server can generate an activity record associating the activity of the computing device with identifications of respective components of the computing device confirmed via validation of the identity data.