Secure Storage Firmware for Data Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage systems are vulnerable to malware attacks, which can subvert data integrity checks and provide false information, as sophisticated malware can control processing systems and mask the presence or contents of files, lacking application-specific protection and secure data configuration.

Innovation Solution

A secure tunnel is established between an agent and a secure storage system within a data storage device, using firmware in a protected environment to manage data, allowing agents to access raw, unadulterated data and compare it to potentially modified information, ensuring data integrity through cryptographic hashes and trusted APIs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional storage systems are used with operating system APIs, then ease of operation is improved, but reliability deteriorates due to malware attacks and data integrity issues

Engineering Contradiction:
Improveease of operationVSAvoidreliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent divides the storage system into two distinct components: a traditional file system accessible by the operating system and a secure storage area protected by firmware. This segmentation allows the OS to continue using standard APIs for general file operations while critical data integrity information is isolated in the secure storage area, preventing malware from corrupting both systems simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces firmware as an intermediary layer between the operating system and the storage device. This firmware acts as a trusted mediator that manages the secure storage area, verifying data integrity through cryptographic hashes and preventing unauthorized access or modification by the OS or malware running on it.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If data is made accessible through operating system APIs, then ease of operation is improved, but security deteriorates as malware can read, copy, or alter stored data

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The storage system is segmented into a standard file system and a secure storage area. The secure storage area contains critical data integrity information (such as cryptographic hashes) that is isolated from the main file system, preventing malware that compromises the OS from accessing or corrupting the integrity verification data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure storage area creates an inert or protected environment for storing critical data integrity information. This area is inaccessible to the operating system and malware, providing a secure enclave where data cannot be read, copied, or altered by unauthorized software, much like an inert atmosphere protects sensitive materials from contamination.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

3Measurement precision

If data integrity checks are performed using operating system commands, then measurement precision is improved, but reliability deteriorates because malware can subvert these checks and provide false information

Engineering Contradiction:
Improvemeasurement precisionVSAvoidreliability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The firmware acts as a trusted intermediary that performs data integrity verification independently of the operating system. It uses cryptographic hashes stored in the secure storage area to verify data integrity, providing a reliable measurement that cannot be subverted by malware since the verification process and stored hashes are protected from OS-level attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the data integrity verification function from the operating system environment and places it in the protected firmware layer. By taking out the critical integrity checking mechanism from the vulnerable OS environment and embedding it in the secure firmware, the system achieves reliable and precise data integrity measurements that are immune to malware subversion.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If secure storage is implemented beyond operating system reach, then reliability is improved, but device complexity increases due to firmware and secure tunnel requirements

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The firmware in the storage device performs multiple functions: it manages the secure storage area, verifies data integrity using cryptographic hashes, and provides a protected interface for the operating system. By consolidating these security and storage management functions into a single firmware layer, the patent achieves high reliability without proportionally increasing complexity, as the firmware serves universal purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10091213B2Systems and methods to provide secure storage
Publication Date: 2018.10.02 SK HYNIX NAND PRODUCT SOLUTIONS CORP
  • US10091213B2 patent drawing
  • US10091213B2 patent drawing
  • US10091213B2 patent drawing

AI summary

Systems and method to provide secure storage are disclosed. An example method includes establishing a secure tunnel between a storage device and an agent, provide a command from the agent to the storage device via the secure tunnel, access first data at the storage device in response to the command, and identify a modification to data stored on the storage device by comparing the first data to second data, wherein the comparison is done using the storage device.