Storage Device Secure Signal Terminal Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current memory devices lack secure access control mechanisms, allowing malicious programs to potentially access and exploit sensitive data stored in secure areas when operating in shared environments with non-secure modes, leading to data breaches.

Innovation Solution

A storage device with a secure and non-secure mode operation, controlled by a secure signal terminal, where the secure mode restricts access to sensitive data and the non-secure mode allows access to normal data areas, using a processor driven by either a secure or normal OS, and a storage controller that manages this access through dedicated secure signal terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a shared memory environment is used to support both secure and non-secure operations, then device versatility is improved, but data security deteriorates due to potential unauthorized access

Engineering Contradiction:
Improvedevice versatilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The memory space is segmented into distinct secure and non-secure areas with separate access control. The secure area is protected from non-secure mode access through hardware-enforced memory management, while the non-secure area remains accessible for general operations. This segmentation allows the device to support both secure and non-secure applications simultaneously without compromising security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure monitor or trust manager component acts as an intermediary between secure and non-secure applications. This intermediary enforces access policies, mediates resource sharing, and prevents unauthorized access to secure data by non-secure applications, enabling safe coexistence of different security domains.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate secure and non-secure memory devices are used, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines secure and non-secure memory functionalities into a single integrated memory device. This unified architecture provides hardware-enforced security boundaries within one device, eliminating the need for separate secure and non-secure memory components while maintaining strong security guarantees through architectural enforcement of access controls.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The memory device is designed with multi-functionality to serve both secure and non-secure applications through a single interface and unified memory space. The device can dynamically switch between secure and non-secure modes and enforce appropriate access controls, providing universal access while maintaining security through hardware-enforced policies rather than requiring separate dedicated devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional memory access control is used, then ease of operation is maintained, but security against malicious programs deteriorates

Engineering Contradiction:
Improveaccess convenienceVSAvoidmalicious program exploitation
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements preliminary security measures by establishing hardware-enforced access control policies before any access attempts. Secure attributes are assigned to memory regions and access rights are predetermined based on security policies, preventing malicious programs from exploiting memory access vulnerabilities rather than relying on software-based protection that can be compromised.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS10387064B2Storage device, host communicating with the storage device, and electronic device including the storage device
Publication Date: 2019.08.20 SAMSUNG ELECTRONICS CO LTD
  • US10387064B2 patent drawing
  • US10387064B2 patent drawing
  • US10387064B2 patent drawing

AI summary

A storage device includes a connector including a plurality of connection terminals connectable to an external device and a nonvolatile memory including a secure area and a normal area. The secure area is accessible when the secure signal indicates the secure mode, and the normal area is accessible when the secure signal indicates the non-secure mode. One of the plurality of connection terminals corresponds to a secure signal terminal for receiving a secure signal that indicates a secure mode or a non-secure mode.