Secure Memory Switch for Data Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure memory devices face challenges in verifying the integrity of stored data, particularly when the bootloader is compromised, leading to potential security breaches and the need for expensive specialized hardware for secure bus transmission.

Innovation Solution

A secure memory device with a unique device secret stored in a secret area, accessible only under controlled conditions, generates a derived secret using a hashing function like HMAC-SHA-256, allowing authentication without requiring modified pin-outs or special hardware, and enabling secure verification even over an insecure bus.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If specialized hardware is used for secure bus transmission, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces physical security mechanisms (specialized hardware, secure bus transmission) with cryptographic software-based security. The memory device uses standard buses combined with cryptographic operations (hashing, encryption) to achieve security without requiring modified pin-outs or special hardware, thereby reducing device complexity while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent uses standard, widely-available bus interfaces instead of expensive specialized secure hardware. By relying on conventional buses combined with cryptographic protocols, the solution eliminates the need for costly specialized components while achieving comparable or superior security through software-based authentication mechanisms.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If the bootloader is compromised, then data integrity verification fails, but existing systems lack the capability to detect this

Engineering Contradiction:
Improvedata integrity verificationVSAvoidauthentication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary authentication of the bootloader and memory contents before system operation. The secure memory device authenticates the bootloader using cryptographic verification, and the system performs self-authentication by verifying memory contents against stored authentication data, preventing compromised bootloadors from executing undetected.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback mechanisms where the system continuously verifies its own integrity. The secure memory device provides authentication feedback by comparing cryptographic hashes of memory contents with stored reference values, allowing the system to detect and respond to compromises in real-time through authentication status feedback.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12086296B2Switch to control communication between a memory and a secret generator in a memory device
Publication Date: 2024.09.10 MICRON TECHNOLOGY INC
  • US12086296B2 patent drawing
  • US12086296B2 patent drawing
  • US12086296B2 patent drawing

AI summary

A device to secure data storage may include circuitry that switches a communication circuit to a memory from a derived secret generator based on an access command.