Encryption Core Post-Processing for Encrypted Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Flash storage devices cannot perform operations on encrypted data until it is decrypted, limiting post-processing and other operations, and there is a need to provide clear data for processing without interfering with other components.
Innovation Solution
Incorporating an encryption core in the storage device to decrypt and perform post-processing operations on data, with the ability to identify and execute post-processing tags associated with the data, allowing for secure and efficient data processing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted and stored in flash memory, then data security is improved, but post-processing operations cannot be performed on the data
Solution Approach 1:
The patent segments the data processing workflow by separating encryption/decryption operations from post-processing operations. The encryption core handles decryption of encrypted data, and when post-processing is required (indicated by a tag), the clear data is temporarily made available to a post-processing module. This segmentation allows both security (data remains encrypted by default) and versatility (post-processing available when needed) to coexist.
Solution Approach 2:
The patent implements preliminary action by pre-tagging encrypted data with post-processing indicators before storage. When data is retrieved, the encryption core checks for these tags and proactively prepares clear data for post-processing operations before the data leaves the storage device. This eliminates the need to decrypt all data and allows selective post-processing only when required.
2Adaptability or versatility
If data is decrypted for processing, then post-processing operations can be performed, but data security is compromised
Solution Approach 1:
The patent applies local quality by making clear data available only in specific locations and for specific purposes. The post-processing module receives clear data temporarily from the encryption core, performs the required operation, and then the data is re-encrypted or discarded. Clear data never exists in a general accessible state, maintaining security while enabling localized post-processing where absolutely necessary.
Solution Approach 2:
The encryption core acts as an intermediary between the encrypted data in storage and the post-processing module. It selectively decrypts data only when a post-processing tag is present, controls the flow of clear data to the post-processing module, and ensures proper re-encryption or disposal afterward. This intermediary role minimizes the exposure of clear data while enabling required operations.
3Productivity
If clear data is made available for processing, then operations can be performed on the data, but interference with other components occurs
Solution Approach 1:
The patent implements dynamics by making the data flow path adaptive rather than static. The system dynamically routes data based on the presence of post-processing tags: encrypted data follows the normal decryption path to the host, while tagged data is dynamically redirected to the post-processing module after decryption. This dynamic routing enables processing capability while maintaining a simple, interference-free path for standard operations.
Data Source
AI summary
Aspects of a storage device including a memory and an encryption core are provided. The storage device may be configured for providing secure data storage, as well as one or more post-processing operations to be performed with the data. The encryption core, which may be configured to decrypt data, may control execution of one or more post-processing operations using the data. A read command received from a host device may include a tag associated with data identified by the read command. When encrypted data is retrieved from memory according to the read command, the encryption core may decrypt the encrypted data and provide the decrypted data for post-processing based on the tag. A corresponding post-processing operation may return a result when executed using the decrypted data. Rather than raw data identified by the read command, the result may be delivered to the host device in response to the read command.


