Storage Device Attestation Using CDI-Based Certificates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage devices lack effective mechanisms to verify the reliability of host devices and applications, which can lead to security vulnerabilities and data integrity issues.

Innovation Solution

The implementation of a storage device and electronic system that generates and verifies compound device identifiers (CDIs) using public and private keys to authenticate host devices and applications, ensuring the reliability of the host device and applications through attestation processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a storage device implements verification mechanisms for host device reliability and application authenticity, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvehost device reliabilityVSAvoidverification mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a certificate-based intermediary verification system where the storage device obtains host device certificates and application certificates from a trusted authority. These certificates act as intermediaries that contain verified reliability information, allowing the storage device to verify host reliability and application authenticity without implementing complex verification mechanisms itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary verification actions by requiring the storage device to verify host device certificates and application certificates before allowing data access. The verification of host reliability and application authenticity is performed in advance, ensuring that only trusted hosts and applications can access stored data.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the storage device verifies application attestation data and host certificates, then data integrity is improved, but processing time increases

Engineering Contradiction:
Improvedata integrityVSAvoidaccess processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs verification actions in advance by checking host device certificates and application certificates before data access requests are processed. This preliminary verification ensures data integrity while allowing efficient subsequent data access operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where the storage device verifies application attestation data and host certificates, then uses the verification results to control data access. The verification feedback loop ensures that only verified hosts and applications can access data, maintaining integrity while optimizing processing efficiency.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250245354A1Storage device and electronic system including the same
Publication Date: 2025.07.31 SAMSUNG ELECTRONICS CO LTD
  • US20250245354A1 patent drawing
  • US20250245354A1 patent drawing
  • US20250245354A1 patent drawing

AI summary

An electronic system comprising a storage device configured to generate a device public key and a device private key based on a device CDI generated from a device DICE, generate a host certificate including a first device signature generated by signing a host public key with the device private key in response to receiving a request of generating the host certificate including the host public key, and send a request of generating a device certificate including the host certificate and the device public key; and a host device configured to generate the host public key and a host private key based on a host CDI generated by a host DICE, generate the device certificate including a first host signature generated by signing the device public key with the host private key in response to the request of generating the device certificate, and send the device certificate to the storage device.