Smart-Card Security Engine for External Memory Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smart-card devices face limitations in storage capacity and security when using separate memory devices, as protecting data in external memory is more challenging due to exposure of protection algorithms and cryptography keys, making it difficult to maintain the same level of protection against intrusion as integrated devices.

Innovation Solution

A system that integrates a smart-card device with a separate memory device and a controller, where the controller includes a security engine to manage and protect encryption keys, and the memory device is partitioned for secure data storage, with the smart-card device authenticating users and controlling access to ensure secure data handling.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If a separate memory device is used to increase storage capacity, then storage capacity is improved, but security is worsened because protection algorithms and cryptography keys are exposed

Engineering Contradiction:
Improvestorage capacityVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The system is divided into two separate devices: a smart-card device containing the security engine with protection algorithms and cryptography keys, and a separate memory device for data storage. This segmentation ensures that security-critical components remain isolated from the storage medium, preventing exposure of sensitive information while enabling expanded storage capacity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A controller acts as an intermediary between the smart-card device and the memory device. The controller manages data encryption and decryption operations, allowing secure data storage in the external memory without requiring the memory device itself to contain security algorithms or keys. The intermediary enables secure communication while maintaining the separation of security and storage functions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If critical security parameters are stored in external memory, then storage capacity is improved, but protection against intrusion is worsened

Engineering Contradiction:
Improvestorage capacityVSAvoidprotection against intrusion
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

Critical security parameters such as protection algorithms and cryptography keys are extracted from the external memory device and placed exclusively in the smart-card device. This extraction ensures that even if the external memory is compromised, the core security mechanisms remain protected and cannot be accessed or manipulated by external intruders.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system architecture transitions from a single integrated device to a multi-component distributed system operating across different functional dimensions. Security operations occur in the smart-card device dimension while data storage occurs in the memory device dimension, with controlled interaction through the controller. This dimensional separation allows large data storage while maintaining security parameters in a protected dimension.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If integrated memory is used, then security is improved, but storage capacity is worsened due to limited memory capacity

Engineering Contradiction:
ImprovesecurityVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The system merges the strengths of two different approaches: the security protection capabilities of integrated smart-card devices with the large storage capacity of separate memory devices. By combining these components into a unified system with a coordinating controller, the solution achieves both enhanced security through isolated security parameters and expanded storage capacity through external memory.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9413535B2Critical security parameter generation and exchange system and method for smart-card memory modules
Publication Date: 2016.08.09 MICRON TECHNOLOGY INC
  • US9413535B2 patent drawing
  • US9413535B2 patent drawing
  • US9413535B2 patent drawing

AI summary

A storage device contains a smart-card device and a memory device, which is connected to a controller. The storage device may be used in the same manner as a conventional smart-card device, or it may be used to store a relatively large amount of data. The memory device may also be used to store data or instructions for use by the smart-card device. The controller includes a security engine that uses critical security parameters stored in, and received from, the smart-card device. The critical security parameters may be sent to the controller in a manner that protects them from being discovered. The critical security parameters may be encryption and/or decryption keys that may encrypt data written to the memory device and/or decrypt data read from the memory device, respectively. Data and instructions used by the smart-card device may therefore stored in the memory device in encrypted form.