Solid-State Storage Visibility Control via Memory Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Solid-state data storage devices lack effective protection against unauthorized access, leading to potential data loss and security breaches, as they are not designed with robust access control mechanisms, and existing encryption methods can disrupt data usage.

Innovation Solution

A method and system that utilize a memory controller and a security device to dynamically control the visibility of a predetermined memory area, allowing it to be made invisible or visible based on an individual identifier, with a secured command set that only activates the area after authentication, ensuring secure access and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic encryption methods are used to protect data, then data security is improved, but data usability deteriorates due to decryption requirements causing data loss

Engineering Contradiction:
Improvedata securityVSAvoiddata usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The memory is divided into visible and invisible areas, with only the visible area accessible during normal operation. This segmentation allows data to be stored securely in the invisible area while maintaining usability by presenting only necessary data in the visible area, eliminating the need for decryption operations that cause data loss.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A controller acts as an intermediary between the user and the memory data. The controller manages the visible and invisible areas, controlling what data is presented to users and when. This intermediary function enables secure data protection without requiring users to perform decryption operations, thus maintaining data usability while ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If access control mechanisms are added to solid-state storage, then security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security functionality is merged with the existing memory controller rather than being implemented as a separate complex security subsystem. The controller integrates the functions of managing visible and invisible memory areas, authentication, and access control into a single unified component, thereby improving security without significantly increasing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If the entire memory area is made invisible for security, then unauthorized access is prevented, but legitimate access becomes difficult

Engineering Contradiction:
Improveprotection against unauthorized accessVSAvoidauthorized access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The memory area visibility is made dynamic rather than static. The controller can switch between making the memory area visible and invisible based on authentication results and usage requirements. This dynamic control allows the system to provide strong protection when needed while enabling easy authorized access when appropriate, resolving the contradiction between security and usability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP2846286B1Method and data storage system for protecting a fixed body data memory against unauthorized access
Publication Date: 2019.04.10 DEUTSCHE TELEKOM AG
  • EP2846286B1 patent drawingFigure 1
  • EP2846286B1 patent drawingFigure 2
  • EP2846286B1 patent drawingFigure 3

AI summary

The invention relates to a method and a data storage system for protecting at least one predetermined storage area (35; 165) of a solid-state data storage device (30; 160) against unauthorized access. This is achieved by making a predetermined storage area (35; 165) of a solid-state data storage device (30; 160) invisible or visible under the control of an authorized user by means of a defined set of instructions, which can be released by a security device (50; 250), and a defined interaction between a storage controller (45; 155) known per se and the PIN-secured security device (50; 250).