Secure Memory Identity Validation for Subscription Sharing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current authentication methods for communication endpoints with secure memory devices in networks lack robustness against counterfeit, tampering, and unauthorized access, particularly in ensuring the integrity and authenticity of data and devices.

Innovation Solution

Implementing a security server and memory devices with integrated security features that utilize cryptographic computations and access controls to validate identities, prevent unauthorized access, and manage ownership, allowing for secure communication and service access without relying on external processors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If current authentication methods are used for communication endpoints, then device compatibility and ease of operation are maintained, but security against counterfeit and tampering is insufficient

Engineering Contradiction:
Improvesecurity against counterfeit and tamperingVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical/authentication systems with cryptographic computations. Secure memory devices perform cryptographic operations to generate authentication data, replacing physical authentication mechanisms with mathematically secure methods that resist counterfeit and tampering while maintaining system compatibility

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces secure memory devices as intermediaries between communication endpoints and authentication servers. These devices hold cryptographic keys and perform secure computations, acting as a trusted mediator that enhances security without requiring complex changes to the overall authentication architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure memory devices with cryptographic computations are implemented, then data integrity and authenticity are improved, but processing requirements and device complexity increase

Engineering Contradiction:
Improvedata integrity and authenticityVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into distinct functional components: secure memory devices for cryptographic computations, authentication servers for verification, and communication endpoints for operation. This segmentation allows each component to be optimized independently, managing complexity while maintaining high security standards

Inventive Principle:
Principle #1Segmentation

3Reliability

If traditional authentication methods are used, then device simplicity is maintained, but vulnerability to unauthorized access increases

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidauthentication process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where secure memory devices automatically perform cryptographic computations and generate authentication data without requiring manual intervention. The devices self-manage their security credentials and automatically verify authenticity, protecting against unauthorized access while maintaining operational simplicity

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20220131847A1Subscription Sharing among a Group of Endpoints having Memory Devices Secured for Reliable Identity Validation
Publication Date: 2022.04.28 MICRON TECHNOLOGY INC
  • US20220131847A1 patent drawing
  • US20220131847A1 patent drawing
  • US20220131847A1 patent drawing

AI summary

A server system configured to allow a group of endpoints to share a subscription. For example, data can be stored to associate the endpoint group with at least one subscriber identifier. After receiving a validation request containing identity data generated by a memory device configured in an endpoint in the group, the server system can validate the identity data based at least in part on a secret of the memory device. In response to a determination that the identity data is valid, the system can determine that the subscriber identifier is not currently assigned to any endpoint in the group and thus assign, based on the data associating the endpoint group with the subscriber identifier, the subscriber identifier to the endpoint to cause a service offered to an account represented by the subscriber identifier to be provided to the endpoint.