Tamper-Resistant Memory Segmentation for Secure Application Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current memory devices, such as IC cards, have limited memory capacity and require cumbersome procedures for transferring application programs between devices, making it inconvenient to use application programs on different terminal devices without direct access to the IC card.
Innovation Solution
A memory device with a tamper-resistant module and a large capacity nonvolatile memory, featuring a secure area and an authorized area, allows secure storage and access of application programs across multiple devices, enabling efficient data management and authorization for authorized terminals.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in a tamper resistant module, then security is improved, but memory capacity is limited
Solution Approach 1:
The memory device is segmented into two distinct memory areas: a first tamper resistant memory for secure storage of critical data and a second non-tamper resistant memory for bulk data storage. This segmentation allows the system to simultaneously achieve high security for sensitive information while providing large capacity for extensive data storage needs.
2Quantity of substance
If application programs are saved in a terminal device, then memory capacity is effectively utilized, but access procedures become complicated
Solution Approach 1:
The memory device acts as an intermediary between the terminal device and the application programs. It stores backup copies of application programs and provides authorized access to multiple terminal devices without requiring complex transfer procedures. The device includes authorization logic that automatically verifies terminal credentials and grants access rights, eliminating the need for manual program transfers between devices.
3Adaptability or versatility
If application programs are transferred through a network, then device connectivity is improved, but access security is compromised
Solution Approach 1:
The invention extracts the security-critical data storage function from the network environment and places it in a dedicated tamper resistant memory module. This separation ensures that sensitive data remains isolated from network vulnerabilities while still allowing authorized network access through controlled interfaces. The security functions are extracted and embedded directly in the hardware, providing protection independent of network security.
Data Source
AI summary
The present invention provides a memory device that can safely hold much data necessary for using an Application (AP) therein. In the present invention, a memory device includes a first tamper resistant memory 41 that cannot be accessed directly by an electronic device and a second non-tamper resistant memory that cannot be directly accessed by the electronic device. The second memory is used to save data stored in the first memory 41 to. In this memory device, since data necessary for using many APs can be safely held in the device, any terminal device satisfying authorizing conditions can use the data held therein.


