Device Identity via Storage Defect Fingerprinting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current device identification methods, such as passwords and cookies, are vulnerable to compromise and spoofing, necessitating improved techniques to ensure authentic user transactions.
Innovation Solution
The method involves creating a unique device identity by intentionally introducing and utilizing errors in storage blocks, such as in flash memory, to generate a fingerprint that is difficult to replicate, using error maps from repeatedly erasing and programming blocks to create a Bad Blocks List, which is then used for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional device identifiers (cookies, IP addresses) are used for device identification, then the identification process is simple and easy to implement, but the security and reliability of device identification deteriorates due to vulnerability to theft, spoofing, and impersonation
Solution Approach 1:
The patent segments the storage device into multiple blocks and further into cells, creating a hierarchical structure. The identification process segments the storage medium into manageable units that can be individually manipulated and tested, allowing for a more secure fingerprinting mechanism without requiring complete system redesign.
Solution Approach 2:
The patent performs preliminary actions by intentionally creating bad blocks and bad cells before final device identification. The system pre-processes the storage device by erasing and programming blocks to create a unique error pattern, establishing the device fingerprint in advance rather than during the identification process.
Solution Approach 3:
The patent converts the harmful effect of storage errors and defects into a beneficial identification feature. Instead of treating bad blocks and bad cells as mere defects to be avoided, the system utilizes their unique distribution patterns as the basis for device fingerprinting, transforming potential failures into security advantages.
2Reliability
If passwords and user credentials are used for transaction authorization, then user access control is established, but security deteriorates when credentials are guessed or compromised by nefarious individuals
Solution Approach 1:
The patent introduces a device fingerprint as an intermediary between the user credential and the authorization system. Instead of relying solely on user-provided credentials that can be guessed or stolen, the system uses the unique storage device characteristics as a mediating verification layer that binds the transaction to the specific device.
Solution Approach 2:
The patent creates a unique copy of the device's error pattern characteristics as its fingerprint. This fingerprint is a replicated representation of the physical storage medium's unique defects, serving as an unforgeable identifier that travels with the device through transactions.
3Reliability
If device identifiers are used to improve assurance of legitimate user access, then transaction security is enhanced, but the identifiers can be stolen through cross-site scripting attacks and farming attacks
Solution Approach 1:
The patent converts the physical imperfections and manufacturing variations of storage devices, which were previously considered harmful defects, into beneficial unique identifiers. These inherent physical characteristics cannot be replicated through software attacks, providing security against theft and impersonation.
Solution Approach 2:
The patent replaces the software-based device identification system with a physics-based identification mechanism. Instead of using software-generated identifiers that can be replicated, the system uses physical storage medium characteristics (bad blocks, bad cells) that are determined by manufacturing processes and cannot be copied through software attacks.
Data Source
AI summary
Enrolling a device identity is disclosed. A determination is made as to whether one or more areas of a storage device has a sufficient number of faults. If an insufficient number of faults is present, additional faults are generated. Verifying a device identity is also disclosed. A fingerprint based on the presence of one or more permanent faults in a storage device is received. The received fingerprint is compared with one or more stored fingerprints to determine an identity of the device.


