Encryption Key Storage in Data Storage Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage devices face challenges in securely managing encryption keys, particularly in preventing access to encrypted data once it is no longer desired, as existing methods may not effectively render encrypted data unreadable.
Innovation Solution
A data storage device employs an encryption scheme where a portion of the encryption key is stored in EEPROM and the remainder in a one-time writable storage location, such as an eFuse array, allowing modification of the key bits to prevent decryption, thereby ensuring the encrypted data remains inaccessible.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If encryption keys are stored in rewritable storage locations, then key management flexibility is improved, but security is worsened because keys can be modified or recovered
Solution Approach 1:
The encryption key is divided into multiple portions and stored in different storage locations within the data storage device. This segmentation allows the system to balance flexibility and security, as the key can be reconstructed when needed but cannot be fully accessed or modified by external attackers.
Solution Approach 2:
An intermediary component (such as a secure enclave or trusted platform module) is introduced to manage the encryption key portions. This intermediary controls access to key segments, enabling flexible key management operations while maintaining security through controlled access mechanisms.
2Reliability
If encryption keys are stored in secure one-time writable locations, then security is improved, but key management flexibility is worsened
Solution Approach 1:
The encryption key is segmented and distributed across multiple storage locations with different write characteristics. Some portions are stored in one-time writable locations for security, while others are in rewritable locations for management flexibility, achieving both goals through differentiated storage.
Solution Approach 2:
Key portions are pre-stored in secure one-time writable locations during device initialization or manufacturing. This preliminary action ensures high security from the outset, while subsequent key management operations use the pre-established secure foundation to enable controlled flexibility.
3Device complexity
If all encryption key bits are stored in one location, then device complexity is reduced, but security is worsened due to single point of failure
Solution Approach 1:
The encryption key is divided into multiple portions stored in different locations within the device. This segmentation eliminates the single point of failure vulnerability while keeping the overall device complexity manageable through systematic key distribution and reconstruction mechanisms.
Data Source
AI summary
Methods, systems, and devices are described for encryption key storage and modification in a data storage device. A portion of an encryption key may be stored in a first storage medium, and one or more bits of the encryption key may be stored in a one-time writable storage location. Data received at the data storage device may be encrypted using the encryption key, and may be stored in a storage medium. In the event that it is no longer desired to allow users to access the encrypted data stored in the storage medium, the one or more bits of the encryption key stored in a one-time writable storage location may be modified. Such modification thereby prevents decryption of the encrypted data and effectively precludes access to the encrypted data.


