Data Encryption Method, Memory Controller and System for Non-Volatile Memory System

A split encryption method using cache and memory counters in NVM systems encrypts cache data before flushing to non-volatile memory, addressing security vulnerabilities and maintaining performance.

CN115329350BActive Publication Date: 2025-07-15HUAZHONG UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210799701.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-06
Publication Date
2025-07-15
Estimated Expiration
2042-07-06

AI Technical Summary

Technical Problem

The existing counter encryption scheme cannot fully encrypt the cached data of the non-volatile memory system, resulting in the unencrypted data being directly flushed to the memory bus and non-volatile memory after the system crashes or power-down. Attackers can obtain user data and cannot fully protect data security.

Method used

The detached encryption method is adopted, and an additional cache counter is used to generate a cache layer for all cache lines at the time of system startup. The generated cache layer is directly used to fill the cache at one time when the system is running to encrypt and decrypt the data written to the cache. When the system crashes or powers down, the encrypted data is flushed to non-volatile memory. The memory layer is filled at one time when it is needed and used.

Benefits of technology

Without affecting the system's operating performance, it effectively prevents cached data from being leaked when the system crashes, fully guarantees user data security, and avoids the impact of cached data encryption on system performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115329350B_ABST
    Figure CN115329350B_ABST
Patent Text Reader

Abstract

The present invention discloses a data encryption method, a memory controller and a system for a non-volatile memory system, belonging to the field of data storage, including: setting a global cache counter and a memory counter corresponding to a memory row; the cache counter is incremented by 1 after the system crashes and restarts; when the system starts, a cache layer one-time filling corresponding to each cache line is generated by using the cache counter; before writing data into the cache line, the data is encrypted by using the cache layer one-time filling; before writing the data in the cache line into the memory, the data is decrypted by using the cache layer one-time filling, and a corresponding memory layer one-time filling is generated by using the memory counter to encrypt the decrypted data; when the system crashes or loses power, the encrypted data in the cache is directly written into the non-volatile memory. The present invention can prevent the data in the cache from leaking when the system crashes without affecting the operation performance of the non-volatile memory system, and comprehensively ensure the security of user data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of data storage, and more specifically, relates to a data encryption method, a memory controller, and a system for a non-volatile memory system. Background Art

[0002] Due to the limitations of manufacturing processes and the energy overhead of power-on refresh, it is difficult for traditional DRAM memories to continue to expand their capacities to meet the growing data storage requirements. New non-volatile memories (NVMs), such as phase change memories (PCMs), resistive random access memories (ReRAMs), and spin transfer torque random access memories (STT-RAMs), etc., have the advantages of high storage density, access speeds close to DRAMs, and low standby power consumption, and are regarded as the next-generation memory products. NVM products represented by Intel Optane DC Persistent Memory have been introduced to the market and have been widely studied and applied in the industrial community.

[0003] As a non-volatile memory, NVM effectively extends the persistent domain from external memory to memory. At the same time, technologies such as Asynchronous DRAM Refresh (ADR) and ExtendADR (eADR) extend the persistent domain from memory to on-chip caches. For example, ADR and eADR use backup batteries to refresh the data in the CPU cache and the on-chip write queue to NVM when the system crashes.

[0004] In an NVM storage system, an attacker can attack off-chip areas, including the memory bus and non-volatile memory, to illegally obtain data. To protect data confidentiality, existing NVM systems generally use a low-overhead counter encryption scheme to encrypt data. The counter encryption scheme uses an encryption engine to encrypt the memory address and counter of the data to generate a one-time padding (OTP). The counter encryption scheme further uses the OTP to perform data encryption and decryption by XORing with user data.

[0005] Since the existing counter encryption scheme only encrypts memory data and does not encrypt the data in the cache, for non-volatile memory systems based on technologies such as eADR, such an encryption scheme that cannot fully encrypt the data of the non-volatile memory system still cannot fully protect the security of user data. Specifically, when the system crashes or loses power, the encryption engine stops working, but with the support of eADR, the unencrypted data in the cache will be directly refreshed to the memory bus and non-volatile memory, and an attacker can illegally obtain this unencrypted data and user confidential information. Summary of the Invention

[0006] In view of the deficiencies of the prior art and the improvement requirements, the present invention provides a data encryption method, a memory controller, and a system for a non-volatile memory system, aiming to prevent data in the cache from leaking when the system crashes without affecting the running performance of the non-volatile memory system and comprehensively ensuring the security of user data.

[0007] To achieve the above object, according to one aspect of the present invention, a data encryption method for a non-volatile memory system is provided. When the non-volatile memory system crashes or loses power, the data in the CPU cache and the on-chip write queue is flushed to the non-volatile memory. The data encryption method includes:

[0008] Set a global cache counter and a memory counter corresponding to each memory row; the cache counter is incremented by 1 after the system crashes and restarts, and the memory counter is incremented by 1 after generating a one-time fill for the memory layer;

[0009] When the system starts, use the current cache counter to generate a corresponding one-time fill for each cache line in the cache layer;

[0010] During the operation of the system, when writing data to a cache line, encrypt the data with the corresponding one-time fill in the cache layer and then write it to the cache line;

[0011] During the operation of the system, when writing the data in the cache line to the memory, decrypt the data with the corresponding one-time fill in the cache layer, generate a corresponding one-time fill for the memory layer with the memory counter, and encrypt the decrypted data with the generated one-time fill for the memory layer and then write it to the non-volatile memory;

[0012] When the system crashes or loses power, directly write the data encrypted by the one-time fill in the cache layer in the cache to the non-volatile memory.

[0013] Further, the data encryption method for a non-volatile memory system provided by the present invention further includes: after the system crashes and restarts, read back the data encrypted by the one-time fill in the cache layer in the non-volatile memory to the cache.

[0014] Further, the data encryption method for a non-volatile memory system provided by the present invention further includes: during the operation of the system, when reading data from a cache line, decrypt the read data with the corresponding one-time fill in the cache layer and then return it to the upper-layer application.

[0015] Further, the data encryption method for a non-volatile memory system provided by the present invention further includes: during the operation of the system, when reading data from the memory, decrypt the read data with the corresponding one-time fill for the memory layer and then return it to the upper-layer application.

[0016] Further, the generation method of the one-time fill in the cache layer includes:

[0017] Organize the cache line address, the value of the cache counter, and the first padding into a cache layer encryption seed that is the same length as the data plaintext;

[0018] Use an encryption engine to encrypt the cache layer encryption seed to obtain a cache layer one-time padding.

[0019] Further, the cache line address consists of the cache level where the cache line is located, the set number, and the way number.

[0020] Further, the generation method of the memory layer one-time padding includes:

[0021] Organize the memory address, the value of the corresponding memory counter, and the second padding into a memory layer encryption seed that is the same length as the data plaintext;

[0022] Use an encryption engine to encrypt the memory layer encryption seed to obtain a memory layer one-time padding.

[0023] According to another aspect of the present invention, there is provided a memory controller for a non-volatile memory system. The non-volatile memory system flushes the data in the CPU cache and the on-chip write queue to the non-volatile memory when crashing or losing power. The controller includes: a counter management module, a cache layer one-time padding generation module, a cache encryption module, a memory encryption module, and a flush module;

[0024] The counter management module is used to set a global cache counter and a memory counter corresponding to the memory line; the cache counter increments by 1 after the system crashes and restarts, and the memory counter increments by 1 after generating the memory layer one-time padding;

[0025] The cache layer one-time padding generation module is used to generate a corresponding cache layer one-time padding for each cache line using the current cache counter when the system starts;

[0026] The cache encryption module is used to encrypt the data with the corresponding cache layer one-time padding and write it into the cache line when writing data to the cache line during the operation of the system;

[0027] The memory encryption module is used to decrypt the data in the cache line with the corresponding cache layer one-time padding when writing the data in the cache line to the memory during the operation of the system, generate a corresponding memory layer one-time padding using the memory counter, and encrypt the decrypted data with the generated memory layer one-time padding and write it into the non-volatile memory;

[0028] The flush module, when the system crashes or loses power, directly writes the data encrypted by the cache layer one-time padding in the cache to the non-volatile memory.

[0029] Furthermore, the memory controller for the non-volatile memory system provided by the present invention further includes: a recovery module, configured to read back the data encrypted by using the cache layer in one-time filling in the non-volatile memory after the system crashes and restarts, into the cache.

[0030] According to another aspect of the present invention, a storage system is provided, including: a non-volatile memory system, and the memory controller for the non-volatile memory system provided by the present invention.

[0031] Generally speaking, through the above technical solutions conceived by the present invention, the following beneficial effects can be achieved:

[0032] (1) By setting an additional cache counter, the present invention encrypts the cache data, and when the system starts up, uses the cache counter to generate corresponding cache layer one-time fillings for each cache line respectively. Then, during the system operation, directly uses the generated cache layer one-time fillings to encrypt the data written into the cache. After the system crashes or loses power, when the data in the cache is refreshed to the non-volatile memory, since the data has been encrypted, it can effectively avoid data leakage and protect the security of the data. Compared with the on-demand generation of one-time fillings and data encryption when writing data in the memory, the encryption of the cache data in the present invention is a separated encryption, that is, separates the process of generating one-time fillings, which is time-consuming and has large overhead, from the process of using one-time fillings to encrypt data, and the generation of one-time fillings is only executed when the system starts up, which makes the delay of generating the cache layer one-time fillings not affect the system operation performance. Generally speaking, the present invention can prevent the data in the cache from leaking when the system crashes without affecting the operation performance of the non-volatile memory system, and comprehensively ensure the security of user data.

[0033] (2) The cache counter set by the present invention is only updated when the system crashes and restarts, and this update overhead does not affect the operation performance of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a schematic diagram of a data encryption method for a non-volatile memory system provided by an embodiment of the present invention;

[0035] Figure 2 It is a schematic diagram of separated encryption provided by an embodiment of the present invention.

[0036] Figure 3 It is a schematic diagram of generating cache layer one-time fillings provided by an embodiment of the present invention; wherein, (a) is a schematic diagram of the cache line position, and (b) is a schematic diagram of generating cache layer one-time fillings. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention. In addition, the technical features involved in the various embodiments of the present invention described below can be combined with each other as long as they do not conflict with each other.

[0038] In the present invention, terms such as "first", "second", etc. (if any) in the present invention and the accompanying drawings are used to distinguish similar objects and do not necessarily need to describe a specific order or sequence.

[0039] To solve the technical problem that the counter encryption scheme cannot fully encrypt the data of the non-volatile memory system based on technologies such as eADR, resulting in the incomplete security guarantee of user data, the present invention provides a data encryption method, a memory controller and a system for a non-volatile memory system. The overall idea is as follows: adopt a split encryption method to encrypt the cache data, that is, at system startup, use an additional cache counter to generate a one-to-one cache layer one-time fill for all cache lines. During system operation, directly use the generated cache layer one-time fill to encrypt and decrypt the data written to the cache, so that when the cache data is directly flushed to the non-volatile memory during system crash, the data security can still be guaranteed, and the impact of cache data encryption on system operation performance can be avoided.

[0040] The non-volatile memory system used in the data encryption method, memory controller and system for a non-volatile memory system provided by the present invention has the following characteristics: the non-volatile memory system flushes the data in the CPU cache and the on-chip write queue to the non-volatile memory when crashing or powering off. Among them, a typical one is the non-volatile memory system based on the eADR technology. Without loss of generality, in the following embodiments, the non-volatile memory system based on the eADR technology is taken as an example for illustration.

[0041] The following are embodiments.

[0042] Embodiment 1:

[0043] A data encryption method for a non-volatile memory system, as Figure 1 shown, includes:

[0044] Set a global cache counter and a memory counter corresponding to the memory line; the cache counter increments by 1 after the system crashes and restarts, and the memory counter increments by 1 after generating the memory layer one-time fill;

[0045] When the system starts up, use the current cache counter to generate a corresponding cache layer one-time fill for each cache line;

[0046] During the operation of the system, when writing data to a cache line, the corresponding cache layer is used to fill the encrypted data into the cache line at one time.

[0047] During the operation of the system, when writing the data in the cache line to the memory, the corresponding cache layer is used to fill the decrypted data at one time, and a corresponding memory layer one-time padding is generated by using a memory counter. The decrypted data is encrypted by using the generated memory layer one-time padding and then written to the non-volatile memory.

[0048] When the system crashes or loses power, the data encrypted by the cache layer one-time padding in the cache is directly written to the non-volatile memory.

[0049] In order to facilitate the normal execution of the upper-layer application after the system crashes and restarts, the data encryption method for the non-volatile memory system provided in this embodiment further includes: after the system crashes and restarts, reading back the data encrypted by the cache layer one-time padding in the non-volatile memory to the cache.

[0050] In this embodiment, an additional cache counter is set to encrypt the cache data. At the startup of the system, the cache counter is used to generate corresponding cache layer one-time padding for each cache line respectively. Then, during the operation of the system, the generated cache layer one-time padding is directly used to encrypt the data written to the cache. After the system crashes or loses power, when the data in the cache is refreshed to the non-volatile memory, since the data has been encrypted, it can effectively avoid data leakage and protect the security of the data. Compared with the on-demand generation of one-time padding and data encryption when writing data in the memory, as Figure 2 shown, the encryption of the cache data in this embodiment is a separated encryption, that is, the generation process of the one-time padding, which is time-consuming and has a large overhead, is separated from the process of using the one-time padding for data encryption, and the generation of the one-time padding is only executed at the startup of the system, which makes the delay of generating the cache layer one-time padding not affect the system operation performance.

[0051] As Figure 3 shown, in this embodiment, the generation method of the cache layer one-time padding includes:

[0052] Combining the cache line address, the value of the cache counter, and the first padding into a cache layer encryption seed with the same length as the data plaintext, as shown in (b) of Figure 3 ; the content of the first padding can be set according to the actual application.

[0053] The encryption engine is used to encrypt the cache layer encryption seed to obtain the cache layer one-time padding; optionally, in this embodiment, the encryption engine for generating the cache layer one-time padding is specifically an AES encryption engine; after generating the cache layer one-time padding, the cache layer one-time padding is used to perform an exclusive OR operation with the data written into the cache, so as to encrypt the data in the cache;

[0054] As Figure 3 As shown in (a) of , in this embodiment, the cache line address is composed of the cache level where the cache line is located, the group number, and the way number;

[0055] Similar to the generation process of the cache layer one-time padding, in this embodiment, the generation method of the memory layer one-time padding includes:

[0056] The memory address, the value of the corresponding memory counter, and the second padding are organized into a memory layer encryption seed with the same length as the data plaintext; similarly, the content of the second padding can be set according to the actual application;

[0057] The encryption engine is used to encrypt the memory layer encryption seed to obtain the memory layer one-time padding; optionally, in this embodiment, the encryption engine for generating the memory layer one-time padding is the same as the encryption engine for generating the cache layer one-time padding, specifically an AES encryption engine; after generating the memory layer one-time padding, the memory layer one-time padding is used to perform an exclusive OR operation with the data written into the memory, so as to encrypt the data in the memory;

[0058] Different from the generation of the cache layer one-time padding, the memory layer one-time padding is generated on demand during system operation, that is, it is generated only when it is necessary to use the memory layer one-time padding for data encryption.

[0059] In this embodiment, during normal system operation, the data in the non-volatile memory is encrypted using the memory layer one-time padding, and only when the system crashes or loses power, there will be some data in the memory that is encrypted using the cache layer one-time padding. After the system crashes and restarts, the metadata can be used to identify which one-time padding is specifically used to encrypt the data in the non-volatile memory.

[0060] The data encryption method for the non-volatile memory system provided in this embodiment further includes: during the operation of the system, when reading data from the cache line, the data read is decrypted using the corresponding cache layer one-time padding and then returned to the upper-layer application; the method for decrypting the data in the cache is specifically: performing an exclusive OR operation with the corresponding cache layer one-time padding and the data read from the cache;

[0061] The data encryption method for a non-volatile memory system provided in this embodiment further includes: during the operation of the system, when reading data from the memory, the corresponding memory layer is used to fill in once to decrypt the read data and then return it to the upper-layer application; the specific method for decrypting the data in the memory is: using the corresponding memory layer to fill in once and performing an exclusive OR operation with the data read from the memory.

[0062] Generally speaking, this embodiment uses a split encryption method to encrypt the data in the non-volatile memory system. The process of generating the cache layer fill-in once is only executed when the system starts, and the counter is only updated when the system crashes and restarts. It can prevent the data in the cache from leaking when the system crashes without affecting the running performance of the non-volatile memory system, and comprehensively ensure the security of user data.

[0063] Embodiment 2:

[0064] A memory controller for a non-volatile memory system, where the non-volatile memory system flushes the data in the CPU cache and the on-chip write queue to the non-volatile memory when crashing or losing power; the controller includes: a counter management module, a cache layer fill-in once generation module, a cache encryption module, a memory encryption module, a flush module, and a recovery module;

[0065] The counter management module is used to set a global cache counter and a memory counter corresponding to the memory row; the cache counter increments by 1 after the system crashes and restarts, and the memory counter increments by 1 after generating the memory layer fill-in once;

[0066] The cache layer fill-in once generation module is used to generate the corresponding cache layer fill-in once for each cache row using the current cache counter when the system starts;

[0067] The cache encryption module is used to encrypt the data using the corresponding cache layer fill-in once and write it into the cache row when writing data to the cache row during the operation of the system;

[0068] The memory encryption module is used to decrypt the data in the cache row using the corresponding cache layer fill-in once when writing the data in the cache row to the memory during the operation of the system, generate the corresponding memory layer fill-in once using the memory counter, and encrypt the decrypted data using the generated memory layer fill-in once and write it into the non-volatile memory;

[0069] The flush module, when the system crashes or loses power, directly writes the data encrypted by the cache layer fill-in once in the cache into the non-volatile memory;

[0070] The recovery module is used to read back the data encrypted by the cache layer fill-in once in the non-volatile memory into the cache after the system crashes and restarts;

[0071] In this embodiment, for the specific implementation manners of each module, reference may be made to the description in the above method embodiment, and details will not be repeated here.

[0072] Embodiment 3:

[0073] A storage system includes: a non-volatile memory system, and the memory controller for the non-volatile memory system provided in the above Embodiment 2.

[0074] Those skilled in the art can easily understand that the above are only preferred embodiments of the present invention, and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.

Claims

1. A data encryption method for a non-volatile memory system, where the non-volatile memory system flushes the data in the CPU cache and the on-chip write queue to the non-volatile memory when a crash or power failure occurs; characterized in that, The described data encryption method includes: Setting a global cache counter and a memory counter corresponding to a memory line; the cache counter increments by 1 after the system crashes and restarts, and the memory counter increments by 1 after generating a memory layer one-time fill; When the system starts, using the current cache counter to generate a corresponding cache layer one-time fill for each cache line; During the operation of the system, when writing data to a cache line, encrypting the data with the corresponding cache layer one-time fill and then writing it to the cache line; During the operation of the system, when writing the data in the cache line to memory, decrypting the data with the corresponding cache layer one-time fill, generating a corresponding memory layer one-time fill using the memory counter, and encrypting the decrypted data with the generated memory layer one-time fill and then writing it to non-volatile memory; When the system crashes or loses power, directly writing the data encrypted by the cache layer one-time fill in the cache to non-volatile memory.

2. The data encryption method for a non-volatile memory system according to claim 1, wherein It further includes: After the system crashes and restarts, reading back the data encrypted by the cache layer one-time fill in the non-volatile memory to the cache.

3. The data encryption method for a non-volatile memory system as claimed in claim 1 or 2, wherein, It further includes: During the operation of the system, when reading data from a cache line, decrypting the read data with the corresponding cache layer one-time fill and then returning it to the upper-layer application.

4. The data encryption method for a non-volatile memory system according to claim 3, characterized in that, It further includes: During the operation of the system, when reading data from memory, decrypting the read data with the corresponding memory layer one-time fill and then returning it to the upper-layer application.

5. The data encryption method for a non-volatile memory system according to claim 1 or 2, characterized in that, The generation method of the cache layer one-time fill includes: Organizing the cache line address, the value of the cache counter, and a first fill into a cache layer encryption seed with the same length as the data plaintext; Using an encryption engine to encrypt the cache layer encryption seed to obtain the cache layer one-time fill.

6. The data encryption method for a non-volatile memory system according to claim 5, wherein The cache line address consists of the cache level where the cache line is located, the set number, and the way number.

7. The data encryption method for a non-volatile memory system according to claim 1 or 2, characterized in that The generation method of the memory layer one-time fill includes: Organizing the memory address, the value of the corresponding memory counter, and a second fill into a memory layer encryption seed with the same length as the data plaintext; Using an encryption engine to encrypt the memory layer encryption seed to obtain the memory layer one-time fill.

8. A memory controller for a non-volatile memory system, the non-volatile memory system flushing data in a CPU cache and an on-chip write queue to non-volatile memory upon a crash or power loss; characterized in that, The controller includes: a counter management module, a cache layer one-time fill generation module, a cache encryption module, a memory encryption module, and a refresh module; The counter management module is used to set a global cache counter and a memory counter corresponding to a memory line; the cache counter increments by 1 after the system crashes and restarts, and the memory counter increments by 1 after generating a memory layer one-time fill; The cache layer one-time fill generation module is used to, when the system starts, use the current cache counter to generate a corresponding cache layer one-time fill for each cache line; The cache encryption module is used to, during the operation of the system, when writing data to a cache line, encrypt the data with the corresponding cache layer one-time fill and then write it to the cache line; The memory encryption module is used to, during the operation of the system, when writing the data in the cache line to memory, decrypt the data with the corresponding cache layer one-time fill, generate a corresponding memory layer one-time fill using the memory counter, and encrypt the decrypted data with the generated memory layer one-time fill and then write it to non-volatile memory; When the system crashes or loses power, the refresh module directly writes the data encrypted by the cache layer in one-time filling in the cache into the non-volatile memory.

9. The memory controller for a non-volatile memory system according to claim 8, wherein It further includes: A recovery module, configured to read back the data encrypted by the cache layer in one-time filling in the non-volatile memory into the cache after the system crashes and restarts.

10. A storage system, characterized in that, It includes: A non-volatile memory system, and the memory controller for the non-volatile memory system according to claim 8 or 9.