Thread Network Dataset Security via Segmented Memory
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Thread network devices face security challenges due to the storage of sensitive datasets in persistent flash memory, which can be compromised, and the network processor's need for frequent access to these datasets increases operational complexity and power consumption.
Innovation Solution
Implementing a secure storage memory with first-level security protection for the host processor and a volatile memory with second-level security protection for the network processor, where the network processor manages network functions based on a dataset with reduced security protection to enhance operational efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If sensitive datasets are stored in persistent flash memory with high security protection, then security is improved, but operational complexity and power consumption increase due to frequent access requirements
Solution Approach 1:
The patent segments the dataset into two copies: a first dataset stored in secure persistent flash memory with high security protection, and a second dataset stored in volatile memory with reduced security protection. The network processor accesses only the second dataset for operational functions, eliminating frequent access to the securely protected first dataset and thereby reducing operational complexity while maintaining security.
Solution Approach 2:
The second dataset in volatile memory acts as an intermediary between the network processor and the first dataset in secure flash memory. The network processor manages network functions by accessing the second dataset, which mediates operational requirements without requiring direct access to the securely protected first dataset, thus reducing operational complexity and power consumption.
2Productivity
If the network processor frequently accesses the dataset in persistent flash memory, then operational efficiency is improved, but power consumption increases
Solution Approach 1:
The patent divides the dataset into two separate copies stored in different memory types. The network processor frequently accesses the second dataset in volatile memory for operational efficiency, while the first dataset remains in persistent flash memory with high security protection. This segmentation enables frequent access without the power penalty of accessing secure flash memory repeatedly.
Solution Approach 2:
The patent creates a copy of the first dataset and stores it as a second dataset in volatile memory. This copying allows the network processor to access the dataset rapidly for operational functions without repeatedly accessing the power-intensive persistent flash memory, thereby improving operational efficiency while reducing power consumption.
3Reliability
If the network processor manages network functions directly with high-security datasets, then security is maintained, but operational complexity increases
Solution Approach 1:
The second dataset in volatile memory serves as an intermediary that simplifies operations for the network processor. The processor manages network functions by accessing this second dataset with reduced security protection, which mediates between the operational simplicity requirement and the security requirement enforced by the first dataset in secure flash memory.
Solution Approach 2:
The patent applies different security protection levels to different copies of the dataset according to their specific uses. The first dataset has high security protection for secure storage, while the second dataset has reduced security protection optimized for operational access by the network processor. This local differentiation of security quality simplifies operations while maintaining overall security.
Data Source
AI summary
Some aspects of this disclosure relate to implementing a thread device that can associate with a thread network. The thread device includes a network processor, a first memory, and a host processor communicatively coupled to the network processor and the first memory. The first memory can be a nonvolatile memory with a first level security protection, and configured to store a first dataset including thread network parameters for the network processor to manage network functions for the thread device associated with the thread network. The network processor can be coupled to a second memory to store a second dataset having a same content as the first dataset. The network processor is configured to manage the network functions based on the second dataset. The second memory can be a volatile memory with a second level security protection that is less than the first level security protection.


