UFS RPMB Authentication Modes for Secure High-Speed Storage Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage devices lack a robust security function with improved speed and efficiency, particularly in managing data access and authentication for Replay Protected Memory Blocks (RPMBs).
Innovation Solution
Incorporating a nonvolatile memory device with a Replay Protected Memory Block (RPMB) and a memory controller that processes UFS Protocol Information Units (UPIUs) for secure data storage and retrieval, including a basic header segment with a data segment length field for enhanced authentication and data management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional storage devices use basic authentication mechanisms for RPMB access, then device complexity is low, but security strength is insufficient
Solution Approach 1:
The patent implements multiple authentication modes (normal mode, advanced mode, high-speed mode) that change the parameters of the authentication mechanism. Each mode uses different authentication methods and processing speeds, allowing the system to adapt between security strength and processing speed based on operational requirements, thereby resolving the contradiction between enhanced security and maintained simplicity.
Solution Approach 2:
The system dynamically selects and switches between different authentication modes depending on the operational context. The memory controller can transition between normal mode, advanced mode, and high-speed mode based on the specific access requirements, enabling the authentication mechanism to adapt its complexity and speed dynamically rather than being fixed, thus balancing security and performance.
2Reliability
If storage devices implement comprehensive authentication for RPMB access, then security is improved, but data access speed decreases
Solution Approach 1:
The patent introduces dynamic mode switching that allows the system to select between different authentication speeds based on operational needs. The memory controller can operate in normal mode for balanced security and speed, advanced mode for enhanced security with acceptable speed, or high-speed mode for rapid access when security requirements are met, thereby dynamically optimizing the trade-off between security and speed.
Solution Approach 2:
By changing the operational parameters through different authentication modes, the system can adjust the balance between security verification depth and data access speed. The high-speed mode uses optimized authentication parameters that maintain security while significantly improving access speed, allowing the system to resolve the contradiction between these two parameters.
3Productivity
If storage devices use simplified authentication processes, then processing speed is maintained, but authentication robustness is reduced
Solution Approach 1:
The system dynamically adapts the authentication process complexity based on the operational context and available resources. When processing speed is critical and security requirements are met through other means, the system can use high-speed mode with optimized authentication. When robustness is more important, the system switches to advanced mode with enhanced verification, thus dynamically balancing productivity and reliability.
Solution Approach 2:
The authentication process is segmented into different modes (normal, advanced, high-speed) that can be selectively applied. This segmentation allows the system to use simplified authentication only when appropriate, while resorting to more robust authentication methods when needed, thereby maintaining overall processing efficiency while ensuring security robustness where required.
4Adaptability or versatility
If storage devices implement multiple authentication modes, then adaptability is improved, but device complexity increases
Solution Approach 1:
The memory controller is designed with multi-functionality to handle multiple authentication modes through a unified control architecture. The same controller hardware and software framework support normal mode, advanced mode, and high-speed mode, reducing the need for separate dedicated circuits for each mode. This universal design enables mode adaptability while minimizing the increase in device complexity.
Solution Approach 2:
The dynamic mode selection mechanism allows the system to adapt to different operational requirements without requiring complex hardware reconfiguration. The controller dynamically switches between modes using software-controlled parameter changes and signal routing, which is less complex than implementing separate hardware paths for each mode, thus achieving adaptability with controlled complexity increase.
Data Source
AI summary
A storage device for providing a security function may include: a nonvolatile memory device including a Replay Protected Memory Block (RPMB); and a memory controller configured for receiving, from an external host, a command UFS Protocol Information Unit (UPIU) including a host RPMB message, and storing data in the RPMB according to authentication performed using the host RPMB message. The command UPIU may include a basic header segment commonly included in UPIUs transmitted/received between the external host and the memory controller, and the basic header segment may include a data segment length field as information indicating that the host RPMB message has been included in the command UPIU.


