Data-Locking Memory Module with Cryptographic Circuit for Secure Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage solutions lack effective mechanisms for secure encryption and decryption of mission-mode data, particularly in scenarios where data integrity must be maintained during power loss or potential security breaches, and there is a need for flexible security policies to balance encryption strength with access latency.
Innovation Solution
The implementation of a data-locking memory module that encrypts mission-mode data in real-time, using a cryptographic circuit to transfer data between mission memory and a nonvolatile memory vault, discarding encryption keys upon security event detection, and utilizing an external key server for decryption, allowing for customizable security policies and granular control over encryption strength.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted and stored in nonvolatile memory, then data security is improved, but data access latency increases
Solution Approach 1:
The system performs preliminary encryption of mission-mode data and stores it in nonvolatile memory vault before potential security threats occur. Encryption keys are pre-generated and stored securely, enabling rapid decryption when needed without compromising security or incurring latency during critical operations.
Solution Approach 2:
A dedicated cryptographic circuit acts as an intermediary between the host system and the encrypted data in nonvolatile memory. This specialized hardware component accelerates encryption and decryption operations, reducing access latency while maintaining strong security through hardware-based cryptographic operations.
2Speed
If encryption keys are retained for quick access, then data access speed is improved, but security is compromised if power is lost or breach occurs
Solution Approach 1:
The system extracts encryption keys from the main memory system and stores them in a separate, secure key storage mechanism within the cryptographic circuit. This physical and logical separation ensures that even if the main system is compromised or experiences power loss, the keys remain protected and cannot be easily extracted by attackers.
Solution Approach 2:
The system dynamically changes the state of encryption keys based on security conditions. Keys are loaded into the cryptographic circuit only when needed for decryption operations and are cleared or invalidated after use. This parameter change approach allows fast access when authorized while maintaining security integrity by ensuring keys are not persistently stored in vulnerable locations.
3Reliability
If strong encryption is applied to all data, then security is improved, but processing overhead and complexity increase
Solution Approach 1:
The system applies strong encryption selectively to mission-mode data that requires security protection, while leaving other data types or less sensitive information in plaintext or with lighter protection. This local quality approach concentrates cryptographic resources on critical data paths, providing strong encryption where needed without unnecessarily increasing overall system complexity and processing overhead.
Solution Approach 2:
The patent replaces software-based encryption implementations with hardware-based cryptographic circuits. This substitution leverages dedicated hardware logic to perform encryption and decryption operations, significantly reducing processing overhead and complexity compared to software implementations while maintaining or improving encryption strength through hardware-optimized algorithms.
Data Source
AI summary
In a memory module, encryption information is received from an external source and stored exclusively within a non-persistent storage element such that the encryption information is expunged from the memory module upon power loss. Write data is received and encrypted using the encryption information stored within the non-persistent storage element to produce encrypted data which is stored, in turn, within a nonvolatile storage of the memory module.


