Integrated Flash Memory Encryption Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing flash memory devices require external cryptographic engines and additional hardware/software for encrypting sensitive data, complicating the encryption process and increasing latency, whereas there is a need for an embeddable solution that can encrypt data at rest without external components.

Innovation Solution

A flash memory device with an integrated encryption engine, static random access memory (SRAM), and a key store, which generates or stores an encryption key, enabling data encryption and decryption within the device without external assistance, using the 256-bit Advanced Encryption Standard (AES) and control circuitry to manage key validation and programming flags.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external cryptographic engine and additional hardware/software are used for encryption, then data security is improved, but device complexity and latency increase

Engineering Contradiction:
Improvedata securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the encryption engine, key store, and flash memory control into a single integrated flash memory device. The encryption engine is embedded within the flash memory controller, allowing encryption/decryption operations to occur internally without requiring separate external cryptographic hardware. This merging eliminates the need for additional external components while maintaining data security through integrated AES encryption capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The flash memory device performs multiple functions: it serves as both storage media and encryption processor. The device can operate in both encrypted and unencrypted modes, and the encryption engine can handle both read and write operations. This multi-functionality eliminates the need for separate dedicated encryption hardware, reducing overall system complexity while maintaining security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If external cryptographic engine is used for encryption, then data security is improved, but encryption process speed deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidencryption process speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By integrating the encryption engine directly into the flash memory controller, data encryption and decryption occur during normal read/write operations without requiring separate processing steps. This eliminates the latency introduced by external cryptographic processors and additional data transfer between components, significantly improving encryption process speed while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If external cryptographic engine and additional components are added, then encryption capability is improved, but system integration complexity increases

Engineering Contradiction:
Improveencryption capabilityVSAvoidsystem integration complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The encryption engine, key store, and control logic are merged into the flash memory device itself, presenting a unified interface to the host system. This integration eliminates the need for multiple separate components and their associated interconnections, simplifying system integration while providing robust AES encryption capability. The device appears as a standard flash memory to the host, requiring no special integration complexity.

Inventive Principle:
Principle #5Merging (Combining)

4Reliability

If data is encrypted before storage in flash memory, then data security is improved, but read/write operation complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidread/write operation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The flash memory device performs encryption and decryption automatically during read/write operations without requiring host system intervention. The control logic within the device determines whether data should be encrypted or decrypted based on the operation type, and the encryption engine processes data internally. This self-service approach maintains data security while keeping read/write operations simple for the host system, which sees no difference in the interface.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3170087B1Flash memory device for storing sensitive information and other data
Publication Date: 2019.05.01 BAE SYSTEMS INFORMATION ANDELECTRONIC SYSTEMS INTEGRATION INC
  • EP3170087B1 patent drawingFigure 1
  • EP3170087B1 patent drawingFigure 2

AI summary

A flash memory process and device for encrypting and storing data in a non-volatile flash memory associated with a host system. The device includes a flash memory, an encryption engine, a key store, a SRAM to interface with the host system, and associated control circuitry. When powered on, the device first determines if a valid encryption key is held in the key store. If a valid key is held in the store, a program flag is set when encrypted data in the flash memory is ready to be decrypted by the engine and stored in the SRAM for use by the host system, or when data originating from the host system and stored in the SRAM is ready to be encrypted by the engine and programmed into the flash memory. The device can be embedded in any host system wherein data must be encrypted while at rest in a memory.