In-Storage Data Encryption Circuit for Secure Processing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data storage devices lack sufficient security functions, making them vulnerable to malicious code attacks and physical hacking, which can disrupt system operations and compromise user data, especially when multiple in-storage programs are installed on the same device.

Innovation Solution

A data storage device equipped with a nonvolatile memory device, volatile memory device, data encryption and decryption circuits, and a processor that controls in-storage program installation, manages a mapping table, and executes programs while encrypting and decrypting data to enhance security by preventing unauthorized access and data leakage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If in-storage processing is implemented without encryption, then processing speed and efficiency are improved, but security performance deteriorates making the device vulnerable to malicious code attacks

Engineering Contradiction:
Improveprocessing speedVSAvoidsecurity performance
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the memory space into multiple isolated regions, each dedicated to a specific in-storage program. This segmentation prevents malicious code from one program from accessing or attacking other programs, thereby maintaining security while enabling parallel processing operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an encryption circuit as an intermediary component between the processor and memory. This circuit encrypts data before it is stored in memory and decrypts it during processing, allowing fast in-storage processing while ensuring that data remains protected from unauthorized access or malicious code.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple in-storage programs are installed in one data storage device, then processing capability and versatility are improved, but security risks worsen due to potential malicious code attacks on other programs

Engineering Contradiction:
Improveprocessing capabilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the memory space into multiple isolated segments, with each segment assigned to a specific in-storage program. This spatial segmentation ensures that even if one program contains malicious code, it cannot access or corrupt other programs' memory spaces, enabling safe coexistence of multiple programs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security attributes to different memory regions. Each memory segment is configured with specific access rights and encryption keys tailored to its associated program, creating localized security zones that protect each program independently while allowing diverse processing capabilities.

Inventive Principle:
Principle #3Local quality

3Reliability

If encryption is applied to all data in memory, then security performance is improved, but processing speed and energy consumption worsen

Engineering Contradiction:
Improvesecurity performanceVSAvoidprocessing speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent performs encryption of data before it is written to memory and decryption before it is read for processing. By performing these cryptographic operations in advance and in parallel with data transfer, the system minimizes the impact on processing speed while maintaining continuous security protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The encryption circuit acts as an intermediary that handles cryptographic operations without blocking the main processing flow. The circuit is designed to encrypt/decrypt data in parallel with data transfer operations, minimizing latency and maintaining high processing throughput while ensuring security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11763041B2Data storage device performing in-storage processing
Publication Date: 2023.09.19 SK HYNIX INC
  • US11763041B2 patent drawing
  • US11763041B2 patent drawing
  • US11763041B2 patent drawing

AI summary

A data storage device includes a nonvolatile memory device, a volatile memory device, a data encryption circuit configured to encrypt data outputted from the nonvolatile memory device, a data decryption circuit configured to decrypt encrypted data output from the data encryption circuit and configured to provide the decrypted data to the volatile memory device, and a processor configured to perform a first process that controls installation of a first in-storage program in the data storage device, a second process configured to manage a mapping table storing a relation between a logical address and a physical address of the nonvolatile memory device, and a third process configured to execute the first in-storage program.