Security Processor Memory Module Secure Token Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security systems and authentication tokens are vulnerable to integrity compromise, leading to system failures and data breaches, particularly due to sophisticated attacks that intercept, corrupt, or publish sensitive information.

Innovation Solution

A system that integrates a security processor with a memory module in a mobile device, creating a secure execution environment for secure token generation, authentication, and transmission, utilizing non-volatile memory partitions with varying access rights and secure communication channels established through mutual authentication with external processors or servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security functionality is implemented using traditional software-based systems, then ease of operation is maintained, but vulnerability to attacks and integrity compromise increases

Engineering Contradiction:
Improvesecurity integrityVSAvoidvulnerability to attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a dedicated security processor as an intermediary component between the external processor and the non-volatile memory. This security processor acts as a mediator that handles all security-critical operations including token generation, authentication, and encrypted data access. By isolating these functions in a separate security domain, the system prevents attackers from compromising the main processor to access security functions, thus resolving the vulnerability issue while maintaining security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the system into distinct security domains: a secure execution environment within the non-volatile memory controlled by the security processor, and the external processor for general operations. This segmentation isolates security-critical functions from potential attack vectors in the external system. The non-volatile memory is further segmented into secure partitions that can only be accessed through the security processor, preventing unauthorized access even if the external processor is compromised.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a dedicated security processor and secure execution environment are implemented, then security integrity and protection against attacks improve, but device complexity increases

Engineering Contradiction:
Improvesecurity integrityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the security processor and non-volatile memory into a single integrated secure execution environment. This consolidation reduces the complexity that would arise from having completely separate security hardware and storage systems. The security processor directly controls the non-volatile memory through dedicated interfaces, eliminating the need for complex external security management systems while maintaining high security integrity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security processor is designed to handle multiple security functions including token generation, authentication verification, encrypted data access, and secure channel establishment. By making the security processor multi-functional, the patent reduces the need for separate dedicated hardware for each security operation, thereby managing device complexity while comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If multiple memory partitions with varying access rights are created, then security control and confidentiality improve, but memory management complexity increases

Engineering Contradiction:
Improveconfidentiality controlVSAvoidmemory management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security processor implements self-service memory management by automatically controlling access to different non-volatile memory partitions based on security credentials and authentication states. The security processor monitors all traffic to and from the non-volatile memory, dynamically granting or denying access rights without external intervention. This self-managed approach simplifies the overall system architecture by eliminating the need for complex external memory management hardware while maintaining strict confidentiality controls through partitioned access rights.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8261091B2Solid-state memory-based generation and handling of security authentication tokens
Publication Date: 2012.09.04 CYPRESS SEMICONDUCTOR CORP
  • US8261091B2 patent drawing
  • US8261091B2 patent drawing
  • US8261091B2 patent drawing

AI summary

An architecture is presented that facilitates secure token generation and transmission capabilities in a mobile device. The system comprises at least one software application that includes a secure token assigned to a specific user and a memory module that communicates with an external processor. A security processor, non-volatile memory component and volatile memory component are integrated to form the memory module that communicates with the external processor. The memory module creates a secure execution environment for the execution of application agents associated with the software application and the secure token. The security processor of the system communicates with the software application and external processor to manage generation, authentication, confidentiality, and transmission of the secure token. And, the non-volatile memory allows the introduction of new tokens and the removal of old tokens.