Storage Module Application Identifier Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage solutions fail to prevent the spread of viruses and malware among authorized entities, as they do not restrict access to data based on application identity, allowing malicious applications to read and transfer infected data.

Innovation Solution

A storage module with a security module and controller that tags data with an application identifier, allowing access only to applications with a matching identifier, ensuring that data can be read and stored securely, thereby preventing unauthorized access and the spread of malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the host encrypts the data before sending it to the storage module, then data security is improved, but the device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption function from the host system and places it within the storage module itself. The storage module now independently performs encryption and decryption operations, eliminating the need for the host to implement encryption capabilities. This reduces host device complexity while maintaining data security through dedicated security hardware within the storage module.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary security layer within the storage module that acts as a mediator between the host and the stored data. This intermediary component handles authentication, encryption, and access control, separating security functions from the host system and reducing overall device complexity while improving reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the storage module stores encrypted data, then data security is improved, but the ease of operation decreases

Engineering Contradiction:
Improvedata securityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The storage module implements self-service by automatically performing encryption and decryption operations without requiring user intervention. The module autonomously manages cryptographic keys, authenticates access requests, and handles data transformation, making encrypted storage as easy to use as traditional storage while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by pre-establishing authentication mechanisms and encryption schemes before data storage operations. The storage module is pre-configured with security protocols and key management systems, so that encrypted storage and retrieval operations can proceed smoothly without requiring users to manually configure security settings or understand cryptographic processes.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If the storage module implements application-specific access control, then the reliability is improved, but the device complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidcontroller complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing access control into distinct application-specific segments. Each application receives dedicated authentication credentials and access permissions, allowing the controller to manage multiple applications independently. This segmented approach improves security by isolating application access while keeping the controller architecture modular and manageable.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage module implements universality by designing a multi-functional authentication system that can handle multiple applications and data types through a unified interface. The controller uses a universal authentication mechanism that works across different applications, reducing complexity compared to implementing separate access control systems for each application while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9626304B2Storage module, host, and method for securing data with application information
Publication Date: 2017.04.18 SANDISK TECHNOLOGIES LLC
  • US9626304B2 patent drawing
  • US9626304B2 patent drawing
  • US9626304B2 patent drawing

AI summary

A storage module, host, and method for securing data with application information are disclosed. In one embodiment, a storage module is provided comprising a memory and a controller. The controller is configured to store data and information about an application that generated the data and allow the data to be read only if information about an application attempting to read the data matches the information about the application that generated the data. Other embodiments are possible, and each of the embodiments can be used alone or together in combination.