Storage Module Application Identifier Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage solutions fail to prevent the spread of viruses and malware among authorized entities, as they do not restrict access to data based on application identity, allowing malicious applications to read and transfer infected data.
Innovation Solution
A storage module with a security module and controller that tags data with an application identifier, allowing access only to applications with a matching identifier, ensuring that data can be read and stored securely, thereby preventing unauthorized access and the spread of malware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the host encrypts the data before sending it to the storage module, then data security is improved, but the device complexity increases
Solution Approach 1:
The patent extracts the encryption function from the host system and places it within the storage module itself. The storage module now independently performs encryption and decryption operations, eliminating the need for the host to implement encryption capabilities. This reduces host device complexity while maintaining data security through dedicated security hardware within the storage module.
Solution Approach 2:
The patent introduces an intermediary security layer within the storage module that acts as a mediator between the host and the stored data. This intermediary component handles authentication, encryption, and access control, separating security functions from the host system and reducing overall device complexity while improving reliability.
2Reliability
If the storage module stores encrypted data, then data security is improved, but the ease of operation decreases
Solution Approach 1:
The storage module implements self-service by automatically performing encryption and decryption operations without requiring user intervention. The module autonomously manages cryptographic keys, authenticates access requests, and handles data transformation, making encrypted storage as easy to use as traditional storage while maintaining high security standards.
Solution Approach 2:
The patent applies preliminary action by pre-establishing authentication mechanisms and encryption schemes before data storage operations. The storage module is pre-configured with security protocols and key management systems, so that encrypted storage and retrieval operations can proceed smoothly without requiring users to manually configure security settings or understand cryptographic processes.
3Reliability
If the storage module implements application-specific access control, then the reliability is improved, but the device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing access control into distinct application-specific segments. Each application receives dedicated authentication credentials and access permissions, allowing the controller to manage multiple applications independently. This segmented approach improves security by isolating application access while keeping the controller architecture modular and manageable.
Solution Approach 2:
The storage module implements universality by designing a multi-functional authentication system that can handle multiple applications and data types through a unified interface. The controller uses a universal authentication mechanism that works across different applications, reducing complexity compared to implementing separate access control systems for each application while maintaining strong security.
Data Source
AI summary
A storage module, host, and method for securing data with application information are disclosed. In one embodiment, a storage module is provided comprising a memory and a controller. The controller is configured to store data and information about an application that generated the data and allow the data to be read only if information about an application attempting to read the data matches the information about the application that generated the data. Other embodiments are possible, and each of the embodiments can be used alone or together in combination.


