In-Storage Data Encryption Circuit for Secure Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data storage devices lack sufficient security functions, making them vulnerable to malicious code attacks and physical hacking, which can disrupt system operations and compromise user data, especially when multiple in-storage programs are installed on the same device.
Innovation Solution
A data storage device equipped with a nonvolatile memory device, volatile memory device, data encryption and decryption circuits, and a processor that controls in-storage program installation, manages a mapping table, and executes programs while encrypting and decrypting data to enhance security by preventing unauthorized access and data leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If in-storage processing is implemented without encryption, then processing speed and efficiency are improved, but security performance deteriorates making the device vulnerable to malicious code attacks
Solution Approach 1:
The patent segments the memory space into multiple isolated regions, each dedicated to a specific in-storage program. This segmentation prevents malicious code from one program from accessing or attacking other programs, thereby maintaining security while enabling parallel processing operations.
Solution Approach 2:
The patent introduces an encryption circuit as an intermediary component between the processor and memory. This circuit encrypts data before it is stored in memory and decrypts it during processing, allowing fast in-storage processing while ensuring that data remains protected from unauthorized access or malicious code.
2Adaptability or versatility
If multiple in-storage programs are installed in one data storage device, then processing capability and versatility are improved, but security risks worsen due to potential malicious code attacks on other programs
Solution Approach 1:
The patent divides the memory space into multiple isolated segments, with each segment assigned to a specific in-storage program. This spatial segmentation ensures that even if one program contains malicious code, it cannot access or corrupt other programs' memory spaces, enabling safe coexistence of multiple programs.
Solution Approach 2:
The patent applies different security attributes to different memory regions. Each memory segment is configured with specific access rights and encryption keys tailored to its associated program, creating localized security zones that protect each program independently while allowing diverse processing capabilities.
3Reliability
If encryption is applied to all data in memory, then security performance is improved, but processing speed and energy consumption worsen
Solution Approach 1:
The patent performs encryption of data before it is written to memory and decryption before it is read for processing. By performing these cryptographic operations in advance and in parallel with data transfer, the system minimizes the impact on processing speed while maintaining continuous security protection.
Solution Approach 2:
The encryption circuit acts as an intermediary that handles cryptographic operations without blocking the main processing flow. The circuit is designed to encrypt/decrypt data in parallel with data transfer operations, minimizing latency and maintaining high processing throughput while ensuring security.
Data Source
AI summary
A data storage device includes a nonvolatile memory device, a volatile memory device, a data encryption circuit configured to encrypt data outputted from the nonvolatile memory device, a data decryption circuit configured to decrypt encrypted data output from the data encryption circuit and configured to provide the decrypted data to the volatile memory device, and a processor configured to perform a first process that controls installation of a first in-storage program in the data storage device, a second process configured to manage a mapping table storing a relation between a logical address and a physical address of the nonvolatile memory device, and a third process configured to execute the first in-storage program.


