Storage Device Authentication Using Dynamic Random Seed Tables

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for authenticating storage devices are vulnerable to hacking due to the use of static, predefined sequences, allowing counterfeit manufacturers to replicate legitimate devices by obtaining and cracking these sequences.

Innovation Solution

A multilevel authentication mechanism using a Random Seed Table (RST) for encrypting and decrypting data exchanged between host and storage devices, with dynamic information generation for each authentication session, making it difficult for counterfeiters to identify patterns and crack the data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a static, predefined sequence is used for authentication, then the authentication process is simple and fast, but the system becomes vulnerable to hacking and counterfeit devices

Engineering Contradiction:
Improveauthentication process simplicityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies dynamics by replacing the static, predefined authentication sequence with a dynamic sequence that changes for each authentication session. The host device generates a random number and uses it to create a unique authentication sequence each time, ensuring that the sequence is not reusable or predictable. This dynamic approach maintains operational simplicity while dramatically improving security against hacking and counterfeit devices.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of the authentication sequence from fixed to variable. Instead of using a constant predefined sequence, the system uses a random number generated for each session as a parameter that changes with each authentication attempt. This parameter change ensures that even if counterfeit devices have stored sequences, they cannot authenticate because the sequence is different each time.

Inventive Principle:
Principle #35Parameter changes

2Stability of the object's composition

If a predefined sequence is programmed into all host devices, then authentication consistency is maintained, but counterfeit manufacturers can easily observe, track, and crack the sequence

Engineering Contradiction:
Improveauthentication consistencyVSAvoidcounterfeit device vulnerability
Core Design Contradiction:
Stability of the object's compositionVSObject-affected harmful factors

Solution Approach 1:

The patent eliminates the harmful factor by introducing dynamic randomness into the authentication sequence. Each host device generates a unique random number for each authentication session, making the sequence unpredictable and impossible to track or crack by counterfeit manufacturers. This maintains authentication consistency for legitimate devices while rendering counterfeit devices vulnerable due to their inability to generate or store the dynamic sequences.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If the same authentication sequence is used across multiple sessions, then system complexity is reduced, but the security against data cracking is compromised

Engineering Contradiction:
Improveauthentication system complexityVSAvoidauthentication data security
Core Design Contradiction:
Device complexityVSLoss of information

Solution Approach 1:

The patent applies dynamics by generating a new random number and authentication sequence for each session, preventing the reuse of sequences across multiple sessions. This dynamic generation maintains relatively low system complexity while ensuring that authentication data from one session cannot be cracked or reused in subsequent sessions, thus preventing information loss and security breaches.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS10242175B2Method and system for authentication of a storage device
Publication Date: 2019.03.26 SAMSUNG ELECTRONICS CO LTD
  • US10242175B2 patent drawing
  • US10242175B2 patent drawing
  • US10242175B2 patent drawing

AI summary

A method for authenticating a storage device includes sending encrypted host device data from a host device to the storage device for a current authentication session, receiving encrypted storage device specific data and an encrypted first output string from the storage device based on the encrypted host device data sent to the storage device, and authenticating the storage device based on the encrypted storage device specific data and the encrypted first output string from the storage device.