Virtualized Authentication for Secure Memory Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory systems face challenges in securely accessing data stored in secure storage devices, particularly for virtual machines that are not physically integrated with the storage device, limiting access and increasing costs due to the need for individual secure storage devices for each system.

Innovation Solution

A virtualized authentication system that uses a secure component with a device identifier generated according to a standard, asymmetric key pairs, and a key management server to authenticate virtual machines, allowing secure access while centralizing secure storage, thereby reducing costs and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual secure storage devices are provided for each system, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal secure storage device that can securely serve multiple virtual machines through cryptographic authentication. The single secure storage device performs multiple functions by generating unique cryptographic keys for each virtual machine and authenticating their access requests, eliminating the need for separate secure storage devices for each system while maintaining security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates virtual copies of authentication capabilities by generating unique cryptographic key pairs for each virtual machine. Instead of physically copying secure storage devices, the system creates virtual authentication instances through cryptographic keys that allow each virtual machine to be authenticated individually, achieving the effect of multiple secure access points from a single physical device.

Inventive Principle:
Principle #26Copying

2Reliability

If individual secure storage devices are provided for each system, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges multiple secure storage functions into a single secure storage device. By combining the authentication and secure storage capabilities for multiple virtual machines into one device, the system reduces the total quantity of hardware needed while maintaining the security level that would otherwise require multiple separate devices.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure storage device is designed with universal functionality to serve multiple virtual machines simultaneously through cryptographic authentication. This multi-functionality allows one device to replace what would traditionally require multiple dedicated secure storage devices, thereby reducing overall system cost while maintaining security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If virtual machines are not physically integrated with the storage device, then adaptability is improved, but access security deteriorates

Engineering Contradiction:
Improveaccess flexibilityVSAvoidaccess security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces cryptographic key pairs as an intermediary mechanism between virtual machines and the secure storage device. This intermediary authentication layer allows virtual machines that are not physically integrated with the storage device to securely access stored data. The cryptographic keys act as mediators that verify the identity and authorization of remote virtual machines, maintaining security despite physical separation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical/physical integration requirement with a cryptographic authentication system. Instead of requiring virtual machines to be physically connected or integrated with the secure storage device, the system uses digital cryptographic keys for authentication. This substitution of physical connection with cryptographic verification enables remote access while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11997217B2Virtualized authentication device
Publication Date: 2024.05.28 MICRON TECHNOLOGY INC
  • US11997217B2 patent drawing
  • US11997217B2 patent drawing
  • US11997217B2 patent drawing

AI summary

Methods, systems, and devices for virtualized authentication device are described. A virtual device (such as a virtual machine) may be permitted to access secured data within a memory device by an authentication process. The memory device may generate cryptographic keys in portions of the memory device and assign the cryptographic keys to the virtual machines. The virtual machine may use an authentication process using the cryptographic keys to access the secure data in the memory device. The authentication process may include authenticating the identity of the virtual machine and the code operating on the virtual machine based upon comparing cryptographic keys received from the virtual machines to the assigned cryptographic keys in the partitions of the memory device. Once both the identity of the virtual machine is authenticated, the virtual machine may be permitted to access the secure data in the memory device.