Single Controller Multi-Client Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile designs face challenges in providing a cost-effective security mechanism for multi-client access to a single storage device through a single controller, as conventional approaches either require expensive dedicated secure elements or multiple access controllers.

Innovation Solution

A security mechanism that uses a single host controller to manage access to a storage device by verifying the identity, command, and logical unit number (LUN) of each client, allowing access to specific partitions based on client privileges, with special clients having exclusive access and regular clients sharing access with others.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dedicated secure element is used to ensure storage element is only accessible by a special client, then security is improved, but system cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem cost
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple secure elements and their access controllers into a single storage device with a unified access controller. The controller implements multiple access control lists (ACLs) that manage permissions for different clients, eliminating the need for separate secure elements while maintaining security through software-based access control mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The access controller is designed to serve multiple clients with different security requirements through a universal interface. It implements both special client access (supervisor mode) and regular client access (user mode) within the same controller, allowing a single device to perform functions that previously required multiple dedicated elements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple storage elements and multiple access controllers are used to provide separate storage for multiple clients, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of components
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple storage elements into a single storage device and consolidates multiple access controllers into one unified controller. The controller manages multiple clients through different access control lists (ACLs), reducing the number of components while maintaining security through logical separation of access rights.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

While physically consolidating components, the patent segments access control through multiple access control lists (ACLs) that are logically separated. Each ACL manages permissions for specific clients, creating virtual segmentation of access rights without requiring physical separation of storage elements or controllers.

Inventive Principle:
Principle #1Segmentation

3Device complexity

If a single controller manages access for multiple clients to a single storage device, then device complexity is reduced, but security control capability may be compromised

Engineering Contradiction:
Improvenumber of controllersVSAvoidaccess control capability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent changes the parameters of access control by implementing multiple access control lists (ACLs) within the single controller. Each ACL contains different permission sets for different clients, allowing the controller to dynamically adjust access parameters based on client identity and security requirements without compromising control capability.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11005936B1Security mechanism for multi-client access to a single storage device through a single controller
Publication Date: 2021.05.11 MEDIATEK INC
  • US11005936B1 patent drawing
  • US11005936B1 patent drawing
  • US11005936B1 patent drawing

AI summary

Examples and techniques pertaining to a security mechanism for multi-client access to a single storage device through a single controller are described. A controller receives a request from a first client of a plurality of clients to access a storage device which stores data associated with the plurality of clients. The controller determines one or more aspects with respect to the first client. The controller then performs one of a plurality of operations including: (a) granting the first client access the storage device responsive to a positive result of the determining, and (b) rejecting the request responsive to a negative result of the determining. The storage device is divided into a plurality of partitions to store respective data associated with each of the plurality of clients in one or more respective partitions of the plurality of partitions.