Storage Device Secure Signal Terminal Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current memory devices lack secure access control mechanisms, allowing malicious programs to potentially access and exploit sensitive data stored in secure areas when operating in shared environments with non-secure modes, leading to data breaches.
Innovation Solution
A storage device with a secure and non-secure mode operation, controlled by a secure signal terminal, where the secure mode restricts access to sensitive data and the non-secure mode allows access to normal data areas, using a processor driven by either a secure or normal OS, and a storage controller that manages this access through dedicated secure signal terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a shared memory environment is used to support both secure and non-secure operations, then device versatility is improved, but data security deteriorates due to potential unauthorized access
Solution Approach 1:
The memory space is segmented into distinct secure and non-secure areas with separate access control. The secure area is protected from non-secure mode access through hardware-enforced memory management, while the non-secure area remains accessible for general operations. This segmentation allows the device to support both secure and non-secure applications simultaneously without compromising security.
Solution Approach 2:
A secure monitor or trust manager component acts as an intermediary between secure and non-secure applications. This intermediary enforces access policies, mediates resource sharing, and prevents unauthorized access to secure data by non-secure applications, enabling safe coexistence of different security domains.
2Reliability
If separate secure and non-secure memory devices are used, then data security is improved, but device complexity increases
Solution Approach 1:
The patent combines secure and non-secure memory functionalities into a single integrated memory device. This unified architecture provides hardware-enforced security boundaries within one device, eliminating the need for separate secure and non-secure memory components while maintaining strong security guarantees through architectural enforcement of access controls.
Solution Approach 2:
The memory device is designed with multi-functionality to serve both secure and non-secure applications through a single interface and unified memory space. The device can dynamically switch between secure and non-secure modes and enforce appropriate access controls, providing universal access while maintaining security through hardware-enforced policies rather than requiring separate dedicated devices.
3Ease of operation
If traditional memory access control is used, then ease of operation is maintained, but security against malicious programs deteriorates
Solution Approach 1:
The system implements preliminary security measures by establishing hardware-enforced access control policies before any access attempts. Secure attributes are assigned to memory regions and access rights are predetermined based on security policies, preventing malicious programs from exploiting memory access vulnerabilities rather than relying on software-based protection that can be compromised.
Data Source
AI summary
A storage device includes a connector including a plurality of connection terminals connectable to an external device and a nonvolatile memory including a secure area and a normal area. The secure area is accessible when the secure signal indicates the secure mode, and the normal area is accessible when the secure signal indicates the non-secure mode. One of the plurality of connection terminals corresponds to a secure signal terminal for receiving a secure signal that indicates a secure mode or a non-secure mode.


