Security Controller for Encrypted Memory Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End-users require secure and high-capacity memory solutions for mobile data storage, with existing technologies lacking effective security measures to protect data from unauthorized access on memory cards and sticks.

Innovation Solution

A security device with a security controller that validates access rights using a codeword, performing encrypted memory access and preventing unauthorized data output by connecting to both a host system and an external memory, ensuring secure data storage and retrieval.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software-based security or multi-package memory control is used, then storage capacity can be increased, but security against unauthorized access is insufficient

Engineering Contradiction:
Improvedata securityVSAvoidsecurity control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security device is introduced as an intermediary component between the host system and the memory system. This security device includes a security controller that validates access rights and controls encrypted memory access, acting as a mediator that enforces security policies without requiring complex software security mechanisms in the host system or memory system itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The memory system is segmented into distinct functional components: a host system, a security device with security controller, and a memory system. This segmentation allows the security controller to independently manage access rights and encryption, separating security functions from storage functions and enabling flexible security control without increasing overall system complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If access rights are validated without encryption, then access control is simple, but data protection during storage and retrieval is insufficient

Engineering Contradiction:
Improvedata protectionVSAvoidencryption mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security controller merges multiple security functions into a single integrated component: access right validation based on codewords, encryption of memory access operations, and control of data input/output. This consolidation provides comprehensive data protection while maintaining relatively simple device architecture, as all security functions are unified in one controller rather than distributed across multiple components.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If unauthorized access is allowed, then system operation is fast and simple, but data security is compromised

Engineering Contradiction:
Improveaccess control securityVSAvoidmemory access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security controller performs preliminary validation of access rights using codewords before allowing any memory access operations. This preliminary check ensures that only authorized access attempts proceed to encryption and memory operations, preventing unauthorized access while maintaining efficient processing for legitimate operations. The validation occurs once per access attempt, minimizing impact on overall access speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8166561B2Security device, secure memory system and method using a security device
Publication Date: 2012.04.24 INFINEON TECHNOLOGIES AG
  • US8166561B2 patent drawing
  • US8166561B2 patent drawing
  • US8166561B2 patent drawing

AI summary

A security device including a first external interface; a second external interface; and a security controller connected to said first external interface and said second external interface, said security controller being adapted to validate an access right based on a codeword received via said first interface to perform an encrypted memory access via said second external interface to an external memory coupleable to said second external interface, and to prevent that encrypted memory access via said first external interface or prevent any output of data via said first external interface depending on data received via said second external interface in case of a negative validation.