Data-Locking Memory Module with Cryptographic Circuit for Secure Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage solutions lack effective mechanisms for secure encryption and decryption of mission-mode data, particularly in scenarios where data integrity must be maintained during power loss or potential security breaches, and there is a need for flexible security policies to balance encryption strength with access latency.

Innovation Solution

The implementation of a data-locking memory module that encrypts mission-mode data in real-time, using a cryptographic circuit to transfer data between mission memory and a nonvolatile memory vault, discarding encryption keys upon security event detection, and utilizing an external key server for decryption, allowing for customizable security policies and granular control over encryption strength.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is encrypted and stored in nonvolatile memory, then data security is improved, but data access latency increases

Engineering Contradiction:
Improvedata securityVSAvoiddata access latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary encryption of mission-mode data and stores it in nonvolatile memory vault before potential security threats occur. Encryption keys are pre-generated and stored securely, enabling rapid decryption when needed without compromising security or incurring latency during critical operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A dedicated cryptographic circuit acts as an intermediary between the host system and the encrypted data in nonvolatile memory. This specialized hardware component accelerates encryption and decryption operations, reducing access latency while maintaining strong security through hardware-based cryptographic operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If encryption keys are retained for quick access, then data access speed is improved, but security is compromised if power is lost or breach occurs

Engineering Contradiction:
Improvedata access speedVSAvoidsecurity integrity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system extracts encryption keys from the main memory system and stores them in a separate, secure key storage mechanism within the cryptographic circuit. This physical and logical separation ensures that even if the main system is compromised or experiences power loss, the keys remain protected and cannot be easily extracted by attackers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system dynamically changes the state of encryption keys based on security conditions. Keys are loaded into the cryptographic circuit only when needed for decryption operations and are cleared or invalidated after use. This parameter change approach allows fast access when authorized while maintaining security integrity by ensuring keys are not persistently stored in vulnerable locations.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If strong encryption is applied to all data, then security is improved, but processing overhead and complexity increase

Engineering Contradiction:
Improveencryption strengthVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies strong encryption selectively to mission-mode data that requires security protection, while leaving other data types or less sensitive information in plaintext or with lighter protection. This local quality approach concentrates cryptographic resources on critical data paths, providing strong encryption where needed without unnecessarily increasing overall system complexity and processing overhead.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent replaces software-based encryption implementations with hardware-based cryptographic circuits. This substitution leverages dedicated hardware logic to perform encryption and decryption operations, significantly reducing processing overhead and complexity compared to software implementations while maintaining or improving encryption strength through hardware-optimized algorithms.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11030118B2Data-locking memory module
Publication Date: 2021.06.08 RAMBUS INC
  • US11030118B2 patent drawing
  • US11030118B2 patent drawing
  • US11030118B2 patent drawing

AI summary

In a memory module, encryption information is received from an external source and stored exclusively within a non-persistent storage element such that the encryption information is expunged from the memory module upon power loss. Write data is received and encrypted using the encryption information stored within the non-persistent storage element to produce encrypted data which is stored, in turn, within a nonvolatile storage of the memory module.