External Memory Controller Encryption Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems with integrated memory controllers have limited encryption key capabilities and proprietary rekeying protocols, which are inadequate for secure data encryption and decryption, especially when the processor is compromised.

Innovation Solution

An external memory controller is used, managed by a key management system, to securely generate and transmit encryption keys, allowing configuration via common protocols independent of the processor manufacturer, enabling secure encryption and decryption of memory regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If an integrated memory controller is used for encryption, then the system benefits from concurrent construction and entangled circuitry, but the system is limited by finite encryption keys and proprietary rekeying protocols

Engineering Contradiction:
Improveconcurrent construction and entangled circuitryVSAvoidencryption key capabilities
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent separates the memory controller from the processor, creating an external memory controller that can be independently configured. This segmentation allows the encryption key management to be decoupled from the processor architecture, enabling flexible key generation and management without being constrained by the processor's proprietary protocols or finite key limitations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a key management system as an intermediary component that generates and manages encryption keys independently. This intermediary system uses common protocols rather than proprietary ones, allowing the external memory controller to receive and manage keys without being bound by the processor manufacturer's specific protocols, thus enhancing adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the entire processor is compromised, then all integrated encryption keys are compromised, but rekeying the integrated memory controller does not adequately address the security lapse

Engineering Contradiction:
ImprovesecurityVSAvoidprocessor architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the encryption key management functionality from the processor by implementing an external memory controller. This extraction ensures that even if the processor is compromised, the encryption keys managed by the external controller remain secure, as they are generated and stored outside the processor architecture. The key management system operates independently, preventing processor compromise from automatically compromising security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If an external memory controller is used, then processor independence and common protocols are achieved, but additional configuration and key management infrastructure is required

Engineering Contradiction:
Improveprocessor independenceVSAvoidkey management infrastructure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a key management system that uses common, known protocols rather than proprietary ones. This universal approach allows the external memory controller to work with multiple processor types and architectures, enhancing processor independence. The system can be configured through standard protocols, making it adaptable to different environments without requiring processor-specific customization.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12147354B2Methods and systems for processor agnostic encryption management
Publication Date: 2024.11.19 DELL PROD LP
  • US12147354B2 patent drawing
  • US12147354B2 patent drawing
  • US12147354B2 patent drawing

AI summary

A method for securing memory via an external memory controller, that includes receiving, by the external memory controller, an allocation request to allocate a memory region from a processor core, and in response to receiving the allocation request, allocating the memory region from the memory, associating the processor core with the memory region, and associating an encryption key and a decryption key with the memory region.