Non-Volatile Storage Firmware Compromise Detection via Bus Latency

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional non-volatile storage devices face challenges in reliably detecting compromised firmware images, as sophisticated malware techniques can evade detection, posing a risk to data security.

Innovation Solution

A method and apparatus that monitor signal traffic on a control bus within a non-volatile storage device, analyzing latency for storage operations to detect anomalies indicative of compromised firmware, with a security chip independent from the storage processor to prevent tampering, and a system comprising a storage controller, security chip, and host interface manager to alert the host of potential threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional malware detection techniques are used, then the storage device can identify security threats, but sophisticated malware can evade detection reducing reliability

Engineering Contradiction:
Improvefirmware compromise detection reliabilityVSAvoidmalware evasion capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A dedicated security chip acts as an intermediary component between the storage processor and the firmware monitoring function. This security chip independently monitors control bus signal traffic and measures latency parameters, providing a separate detection mechanism that is not susceptible to compromise by malware in the storage processor firmware.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces conventional software-based malware detection mechanisms with a hardware-based latency monitoring system. By measuring temporal characteristics of control bus signals and comparing them against established latency profiles, the system detects firmware compromises through physical measurement rather than software analysis, making it resistant to evasion techniques.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If a security chip is added to monitor control bus signal traffic, then detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvefirmware compromise detection reliabilityVSAvoidstorage device architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage device is segmented into functionally independent components: a storage processor for data storage operations and a separate security chip for firmware monitoring. This segmentation allows the security functions to be implemented in dedicated hardware that does not interfere with normal storage operations, managing complexity through functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security chip performs multiple functions including monitoring control bus signal traffic, measuring latency parameters, comparing against latency profiles, and generating security alerts. By consolidating these diverse security functions into a single dedicated component, the patent manages complexity more effectively than implementing separate modules for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11663328B2Detection of compromised storage device firmware
Publication Date: 2023.05.30 SANDISK TECHNOLOGIES LLC
  • US11663328B2 patent drawing
  • US11663328B2 patent drawing
  • US11663328B2 patent drawing

AI summary

An apparatus, system, and method for detecting compromised firmware in a non-volatile storage device. A control bus of a non-volatile storage device is monitored. The non-volatile storage device includes a processor and electronic components coupled to the control bus. Signal traffic on the control bus is analyzed for events and/or triggers related to storage operations initiated on the control bus by the processor. Storage operations include one or more commands directed to at least one of the electronic components. If the latency for the storage operation satisfies an alert threshold a host is notified of compromised firmware.