Secure Storage Account in Non-Volatile Memory Card
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current non-volatile memory cards, such as SIM and R-UIM cards, lack secure access control for high-capacity storage, allowing unauthorized access and copying of digital content due to the absence of advanced security features in additional memory cards like CompactFlash, MMC, SD, or USB Flash Drives.
Innovation Solution
A method and system that utilize a second non-volatile memory device to calculate and manage security credentials, creating a secure storage account on a first non-volatile memory device, ensuring access is restricted using a credential calculated from a memory identification value and account identification value, transmitted between devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If additional high-capacity non-volatile memory is added to storage cards, then storage capacity increases, but security control capability deteriorates due to lack of security features in additional memory devices
Solution Approach 1:
The system divides the storage functionality into two separate components: a high-capacity non-volatile memory device for data storage and a security credential device for access control. This segmentation allows each component to specialize in its function while working together through the host device, resolving the contradiction between storage capacity and security control.
Solution Approach 2:
The host device acts as an intermediary that coordinates between the high-capacity storage device and the security credential device. It manages the challenge-response authentication process and controls access to stored content based on credentials verified through the host, enabling security control without requiring security features in the additional memory device itself.
2Reliability
If security features are integrated into high-capacity SIM cards, then access control capability improves, but device complexity increases
Solution Approach 1:
The security credential functionality is extracted from the high-capacity storage device and placed in a separate security credential device. This extraction simplifies the storage device while maintaining strong access control capabilities through the dedicated security device and host coordination.
Solution Approach 2:
The host device serves multiple functions: it acts as a communication interface between storage and security devices, performs authentication processing, and manages content access control. This multi-functionality consolidates complexity in the host rather than increasing it in the storage or security devices themselves.
3Adaptability or versatility
If standard memory devices like CompactFlash or SD cards are used for additional storage, then storage versatility improves, but security protection deteriorates due to absence of security credentials
Solution Approach 1:
The host device serves as an intermediary that enables standard memory devices to gain security protection. By coordinating authentication between the host, storage device, and security credential device, standard devices can securely store protected content without requiring built-in security features.
Solution Approach 2:
The system implements preliminary authentication through challenge-response credentials before allowing access to stored content. This pre-verification of access rights prevents unauthorized access and copying, protecting content on versatile standard devices without requiring them to have inherent security features.
Data Source
AI summary
In order to create and access a secure storage account in a non-volatile memory device, an account identification value is calculated. A memory identification value is read from a first non-volatile memory device. The memory identification value and the account identification value are transmitted to a second non-volatile memory device, and a calculated credential is received. A command is transmitted to create a secure storage account in the first non-volatile memory device, where the command contains the credential and the account identification value. To access the account, a sequence is transmitted, containing the account identification value and a value based on the credential. A secure storage system contains a first non-volatile memory device that stores a memory identification value and contains a secure partition accessible using a credential, a second non-volatile memory device that can compute the credential, and a host adapted to create and access the secure partition.


