Storage Controller Memory Mutual Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized users can replace memory devices or storage controllers in data storage systems, bypassing security measures and gaining access to host devices, which existing challenge-response authentication protocols fail to prevent effectively.

Innovation Solution

A storage device system that includes memory devices storing a second challenge question and a first response key, with a security module generating and managing challenge requests and responses to ensure mutual authentication, using enable signals to control access and prevent unauthorized access by employing multiple challenges and responses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional challenge-response authentication is used, then authentication capability is provided, but unauthorized users can still replace memory devices or storage controllers and bypass security measures

Engineering Contradiction:
Improvesecurity authenticationVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies mutual authentication where both the storage controller and memory device act as authenticators and authenticatees. Instead of a single-direction challenge-response, the system inverts the traditional model by having each party verify the other's authenticity through cryptographic challenges and responses, preventing unauthorized component replacement

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces cryptographic nonces as intermediaries in the authentication process. These unique, unpredictable values mediate the challenge-response exchange between the storage controller and memory device, ensuring that each authentication instance is unique and cannot be replayed or intercepted by unauthorized users

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If cryptographic nonces are used for authentication, then replay attacks are prevented, but the system complexity increases due to multiple challenges and responses

Engineering Contradiction:
Improveauthentication securityVSAvoidauthentication protocol
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct phases: the storage controller issues a first challenge and verifies the first response, then the memory device issues a second challenge and verifies the second response. This segmentation allows each party to independently verify the other's authenticity without requiring a monolithic complex protocol

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent employs preliminary cryptographic setup where unique nonces are generated and stored in advance in both the storage controller and memory device. This preliminary action ensures that when authentication is needed, the system can quickly exchange challenges and responses without real-time complex computations, reducing operational complexity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10984093B2Memory and controller mutual secure channel association
Publication Date: 2021.04.20 SANDISK TECHNOLOGIES LLC
  • US10984093B2 patent drawing
  • US10984093B2 patent drawing
  • US10984093B2 patent drawing

AI summary

The disclosure describes methods and systems for a storage device that includes one or more memory devices, where the memory devices store a second challenge question and a first response key. The system also includes an interface and a storage controller coupled to the interface and coupled to the memory devices. The storage controller generates an enable signal for enabling access to the memory devices. The system also includes a security module coupled to the storage controller and configured to send and receive challenge requests and challenge responses, where the security module includes a first challenge question and a second response key corresponding to each of the memory devices.