Smart-Card Security Engine for External Memory Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Smart-card devices face limitations in storage capacity and security when using separate memory devices, as protecting data in external memory is more challenging due to exposure of protection algorithms and cryptography keys, making it difficult to maintain the same level of protection against intrusion as integrated devices.
Innovation Solution
A system that integrates a smart-card device with a separate memory device and a controller, where the controller includes a security engine to manage and protect encryption keys, and the memory device is partitioned for secure data storage, with the smart-card device authenticating users and controlling access to ensure secure data handling.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If a separate memory device is used to increase storage capacity, then storage capacity is improved, but security is worsened because protection algorithms and cryptography keys are exposed
Solution Approach 1:
The system is divided into two separate devices: a smart-card device containing the security engine with protection algorithms and cryptography keys, and a separate memory device for data storage. This segmentation ensures that security-critical components remain isolated from the storage medium, preventing exposure of sensitive information while enabling expanded storage capacity.
Solution Approach 2:
A controller acts as an intermediary between the smart-card device and the memory device. The controller manages data encryption and decryption operations, allowing secure data storage in the external memory without requiring the memory device itself to contain security algorithms or keys. The intermediary enables secure communication while maintaining the separation of security and storage functions.
2Quantity of substance
If critical security parameters are stored in external memory, then storage capacity is improved, but protection against intrusion is worsened
Solution Approach 1:
Critical security parameters such as protection algorithms and cryptography keys are extracted from the external memory device and placed exclusively in the smart-card device. This extraction ensures that even if the external memory is compromised, the core security mechanisms remain protected and cannot be accessed or manipulated by external intruders.
Solution Approach 2:
The system architecture transitions from a single integrated device to a multi-component distributed system operating across different functional dimensions. Security operations occur in the smart-card device dimension while data storage occurs in the memory device dimension, with controlled interaction through the controller. This dimensional separation allows large data storage while maintaining security parameters in a protected dimension.
3Reliability
If integrated memory is used, then security is improved, but storage capacity is worsened due to limited memory capacity
Solution Approach 1:
The system merges the strengths of two different approaches: the security protection capabilities of integrated smart-card devices with the large storage capacity of separate memory devices. By combining these components into a unified system with a coordinating controller, the solution achieves both enhanced security through isolated security parameters and expanded storage capacity through external memory.
Data Source
AI summary
A storage device contains a smart-card device and a memory device, which is connected to a controller. The storage device may be used in the same manner as a conventional smart-card device, or it may be used to store a relatively large amount of data. The memory device may also be used to store data or instructions for use by the smart-card device. The controller includes a security engine that uses critical security parameters stored in, and received from, the smart-card device. The critical security parameters may be sent to the controller in a manner that protects them from being discovered. The critical security parameters may be encryption and/or decryption keys that may encrypt data written to the memory device and/or decrypt data read from the memory device, respectively. Data and instructions used by the smart-card device may therefore stored in the memory device in encrypted form.


