Inline Cryptographic Processor for Rapid Storage Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users experience frustration due to the lengthy process of waiting for entire storage devices to be encrypted, which can take several minutes or hours, leading to poor user experiences in various settings where data encryption is desired or required.

Innovation Solution

A method implemented in a trusted runtime of a computing device, isolated from other programs, generates and persists encryption keys across power cycles, using an inline cryptographic processor to encrypt and decrypt data in-line with storage device operations, allowing rapid indication of protection enabled even if parts of the storage device are unencrypted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional encryption methods are used to encrypt entire storage devices, then data security is improved, but user experience deteriorates due to lengthy encryption wait times of several minutes or hours

Engineering Contradiction:
Improvedata securityVSAvoidencryption wait time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the storage device into multiple portions or partitions, allowing encryption to be applied selectively to individual portions rather than requiring encryption of the entire storage device. This segmentation enables faster initialization since only the active portion needs to be encrypted, while other portions can be encrypted in the background or on-demand.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary key generation and encryption setup for storage device portions before data is written to them. The trusted runtime generates encryption keys and provisions them to the cryptographic processor in advance, so that when data needs to be encrypted, the encryption infrastructure is already ready, eliminating lengthy wait times.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If selective encryption of storage device portions is implemented, then encryption speed is improved, but system complexity increases due to key management for multiple portions

Engineering Contradiction:
Improveencryption speedVSAvoidkey management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted runtime as an intermediary layer between the operating system and the cryptographic processor. This trusted runtime manages the complexity of key generation, storage, and provisioning for multiple storage portions, shielding the user and application from the underlying complexity while enabling fast selective encryption.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The cryptographic processor is designed to automatically use the appropriate encryption key from the trusted runtime for each storage portion without requiring manual key selection or management by the user. The system self-manages the key provisioning and selection process, reducing the perceived complexity for users.

Inventive Principle:
Principle #25Self-service

3Reliability

If encryption keys are persisted across power cycles, then data protection is improved, but security risk increases if keys are compromised

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key management functionality from the general operating system environment and places it in a isolated trusted runtime. This separation ensures that even if the main system is compromised, the persisted encryption keys remain protected in the secure, isolated trusted runtime environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted runtime creates a secure, isolated environment (inert atmosphere) for storing and managing encryption keys. This protected environment prevents unauthorized access to persisted keys even when the device is powered off or when the main operating system is compromised, as the trusted runtime maintains security boundaries.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

Data Source

PatentUS10615967B2Rapid data protection for storage devices
Publication Date: 2020.04.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10615967B2 patent drawing
  • US10615967B2 patent drawing
  • US10615967B2 patent drawing

AI summary

A computing device uses a data encryption and decryption system that includes a trusted runtime and an inline cryptographic processor. The trusted runtime provides a trusted execution environment, and the inline cryptographic processor provides decryption and encryption of data in-line with storage device read and write operations. When a portion (e.g., partition) of a storage device is defined, the trusted runtime generates an encryption key and provides the encryption key to the inline cryptographic processor, which uses the encryption key to encrypt data written to the portion and decrypt data read from the portion. Access to the portion can be subsequently protected by associating the key with authentication credentials of a user or other entity. The trusted runtime protects the encryption key based on an authentication key associated with the authentication credentials, allowing subsequent access to the encryption key only in response to the proper authentication credentials being provided.