Device Identity via Storage Defect Fingerprinting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current device identification methods, such as passwords and cookies, are vulnerable to compromise and spoofing, necessitating improved techniques to ensure authentic user transactions.

Innovation Solution

The method involves creating a unique device identity by intentionally introducing and utilizing errors in storage blocks, such as in flash memory, to generate a fingerprint that is difficult to replicate, using error maps from repeatedly erasing and programming blocks to create a Bad Blocks List, which is then used for verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional device identifiers (cookies, IP addresses) are used for device identification, then the identification process is simple and easy to implement, but the security and reliability of device identification deteriorates due to vulnerability to theft, spoofing, and impersonation

Engineering Contradiction:
Improvedevice identification reliabilityVSAvoididentification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the storage device into multiple blocks and further into cells, creating a hierarchical structure. The identification process segments the storage medium into manageable units that can be individually manipulated and tested, allowing for a more secure fingerprinting mechanism without requiring complete system redesign.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by intentionally creating bad blocks and bad cells before final device identification. The system pre-processes the storage device by erasing and programming blocks to create a unique error pattern, establishing the device fingerprint in advance rather than during the identification process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 3:

The patent converts the harmful effect of storage errors and defects into a beneficial identification feature. Instead of treating bad blocks and bad cells as mere defects to be avoided, the system utilizes their unique distribution patterns as the basis for device fingerprinting, transforming potential failures into security advantages.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If passwords and user credentials are used for transaction authorization, then user access control is established, but security deteriorates when credentials are guessed or compromised by nefarious individuals

Engineering Contradiction:
Improvetransaction authorization reliabilityVSAvoidcredential compromise vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a device fingerprint as an intermediary between the user credential and the authorization system. Instead of relying solely on user-provided credentials that can be guessed or stolen, the system uses the unique storage device characteristics as a mediating verification layer that binds the transaction to the specific device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a unique copy of the device's error pattern characteristics as its fingerprint. This fingerprint is a replicated representation of the physical storage medium's unique defects, serving as an unforgeable identifier that travels with the device through transactions.

Inventive Principle:
Principle #26Copying

3Reliability

If device identifiers are used to improve assurance of legitimate user access, then transaction security is enhanced, but the identifiers can be stolen through cross-site scripting attacks and farming attacks

Engineering Contradiction:
Improvelegitimate user verificationVSAvoididentifier theft risk
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent converts the physical imperfections and manufacturing variations of storage devices, which were previously considered harmful defects, into beneficial unique identifiers. These inherent physical characteristics cannot be replicated through software attacks, providing security against theft and impersonation.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent replaces the software-based device identification system with a physics-based identification mechanism. Instead of using software-generated identifiers that can be replicated, the system uses physical storage medium characteristics (bad blocks, bad cells) that are determined by manufacturing processes and cannot be copied through software attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS9442833B1Managing device identity
Publication Date: 2016.09.13 QUALCOMM INC
  • US9442833B1 patent drawing
  • US9442833B1 patent drawing
  • US9442833B1 patent drawing

AI summary

Enrolling a device identity is disclosed. A determination is made as to whether one or more areas of a storage device has a sufficient number of faults. If an insufficient number of faults is present, additional faults are generated. Verifying a device identity is also disclosed. A fingerprint based on the presence of one or more permanent faults in a storage device is received. The received fingerprint is compared with one or more stored fingerprints to determine an identity of the device.