Secure Memory Device for Cryptographic Key Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face security risks due to the exposure and handling of cryptographic keys in file systems, which can lead to unauthorized access and security attacks when used by applications in host systems.

Innovation Solution

A secure memory device with a security manager is used to store and manage cryptographic keys, ensuring they are not exposed outside the memory device, and all cryptographic operations are performed within the secure memory device, using a unique device secret to generate and validate digital signatures, thereby controlling access to secure memory regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If cryptographic keys are stored in the host system's file system for use by applications, then applications can access and use the keys, but security risks increase due to exposure and potential unauthorized access

Engineering Contradiction:
ImproveApplication access to cryptographic keysVSAvoidSecurity risks from key exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts cryptographic keys from the host system's file system and stores them in a dedicated secure memory device. The security manager in the memory device handles key management operations, allowing applications to use keys without direct exposure. This extraction removes keys from the vulnerable file system environment while maintaining application accessibility through controlled interfaces.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The security manager acts as an intermediary between applications and cryptographic keys. Instead of applications directly accessing keys in the file system, they communicate requests to the security manager, which validates and executes operations. This intermediary layer prevents direct key exposure while enabling necessary cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cryptographic keys are exposed in the file system for application use, then applications can perform cryptographic operations, but the system becomes vulnerable to security attacks

Engineering Contradiction:
ImproveApplication cryptographic operations capabilityVSAvoidSystem security against attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments cryptographic key storage and management from the general file system. A dedicated secure memory device with a security manager handles key-related operations separately from application data. This segmentation isolates keys in a protected environment while maintaining cryptographic functionality for applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by creating a specialized secure environment within the memory device specifically for key storage and operations. The security manager provides localized security controls, access validation, and operation management that are tailored to cryptographic requirements, differentiating this region from the general file system.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If cryptographic keys are stored outside the secure memory device, then applications can access them easily, but the risk of unauthorized access and security breaches increases

Engineering Contradiction:
ImproveKey accessibility for applicationsVSAvoidUnauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security manager and key management functionality are nested within the secure memory device. Applications interact with the memory device through standardized interfaces, while the security manager handles key operations internally. This nesting structure keeps keys contained within the secure device while providing application access through controlled interfaces.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11736453B2Secure key storage devices
Publication Date: 2023.08.22 MICRON TECHNOLOGY INC
  • US11736453B2 patent drawing
  • US11736453B2 patent drawing
  • US11736453B2 patent drawing

AI summary

Systems, apparatuses, and methods to establish a secure channel of communication with a remote computer using a memory device having a host system. The memory device stores a first cryptographic key representative of an identity of the host system and a second cryptographic key usable to validate an identity of the remote computer. The memory device controls, based on cryptography and independent of the file system, access to the first cryptographic key and the second cryptographic key. To establish the secure channel, an application running in the host system communicates with the memory device to generate, using the first cryptographic key, a first verification code for a first message of the remote computer without revealing the first cryptographic key to the host system, and to validate, using the second cryptographic key, a second verification code generated by the remote computer for a second message from the application.