Secure Storage Access Mode Matching for Open OS Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing use of open operating systems in electronic devices has weakened data security, leading to frequent instances of data damage and hacking due to vulnerabilities from malicious codes.
Innovation Solution
A storage device with a secure storage area and an access mode memory that includes a memory controller to authenticate and manage access modes, ensuring that only authorized access is granted based on matching device and host access modes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an open operating system is used to provide various services and applications, then ease of operation and versatility are improved, but data security deteriorates due to vulnerabilities from malicious codes
Solution Approach 1:
The storage device is divided into a normal storage area and a secure storage area. The secure storage area is further segmented into a first secure storage area for storing authentication information and a second secure storage area for storing sensitive data. This segmentation isolates security functions from general storage functions, allowing the system to maintain openness for applications while protecting critical data through dedicated secure zones.
Solution Approach 2:
An authentication manager is introduced as an intermediary component between the host device and the secure storage area. The authentication manager receives authentication information from the host, verifies it against stored credentials, and controls access rights to the secure storage area. This intermediary layer enables the open operating system to access secure data without exposing the underlying security mechanisms to potential malware.
2Reliability
If authentication information is stored in the secure storage area, then data security is improved, but device complexity increases due to additional authentication mechanisms
Solution Approach 1:
The authentication manager automatically performs authentication operations without requiring manual intervention. When a host device requests access to the secure storage area, the authentication manager self-service style verifies the authentication information, determines access rights, and enables or disables access accordingly. This automation reduces the operational complexity for users while maintaining strong security.
Solution Approach 2:
The authentication manager combines multiple security functions into a single integrated component: storing authentication information, verifying credentials, determining access rights, and controlling access to the secure storage area. By merging these functions, the system achieves comprehensive security without proportionally increasing complexity, as the authentication manager handles all security-related operations through a unified mechanism.
3Adaptability or versatility
If access mode information is stored in the access mode memory, then adaptability of access control is improved, but loss of information increases due to additional memory requirements
Solution Approach 1:
Different storage areas are assigned different quality characteristics: the access mode memory stores only essential access control information (access mode types and associated keys) rather than complete data copies. The secure storage area stores sensitive data with restricted access. This local quality differentiation ensures that memory space is used efficiently for security-critical information only, minimizing overall information loss while maintaining adaptability in access control.
Data Source
AI summary
According to an embodiment of the present technology, a storage device may include a memory device including a secure storage area for storing therein data to be accessed according to authentication; an access mode memory configured to store therein information of device access mode regarding an operation mode for the secure storage area; and a memory controller configured to receive a command regarding the secure storage area from an external host and process the command according to whether information of host access mode included in the command matches the information of the device access mode.


