In-Line Data-at-Rest Encryption Core for Storage Media
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing out-of-band encryption techniques for Data-at-Rest (DAR) in integrated storage media degrade computing device performance by occupying the host processor and compromising communication paths, leading to reduced throughput and latency.
Innovation Solution
A hardware-based, in-line encryption system that includes an encryption core with a storage device proxy, an encryption engine, and host device proxies, which transparently encrypts data at rest without degrading the host processor's performance by routing data transfer commands based on the encryption state, allowing the host processor to perform other tasks while maintaining encryption integrity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If out-of-band encryption techniques are used to encrypt Data-at-Rest, then encryption security is provided, but the host processor's availability is reduced and throughput/latency performance degrades
Solution Approach 1:
The encryption functionality is extracted from the host processor and implemented as a separate hardware encryption engine within the storage device. This allows the host processor to offload encryption duties and focus on other computational tasks, thereby improving processor availability and overall system throughput while maintaining encryption security through dedicated hardware.
Solution Approach 2:
A communication interface is introduced as an intermediary between the host processor and the encryption engine. This interface handles data transfer and encryption coordination, allowing the host processor to initiate encryption operations without being blocked or occupied during the actual encryption process, thus maintaining high processor availability.
2Reliability
If separate services are used for encrypting Data-at-Rest, then encryption functionality is provided, but communication paths may be compromised and effectiveness reduced
Solution Approach 1:
The encryption engine is merged into the storage device itself, combining storage and encryption functionalities in a single integrated unit. This eliminates the need for separate communication paths between the host processor and external encryption services, thereby reducing the attack surface and preventing communication path compromises while maintaining encryption effectiveness.
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
An improved system (300, 440) for providing transparent, in-line encryption of data-at-rest (DAR) stored by a host controller (220, 420) of a host device (200, 400). An encryption core (320) is instantiated in a hardware device (310) physically coupled to a system board within the host device. The encryption core includes a storage device proxy (330), an encryption engine (340), and a plurality of host device proxies (350A, 350B, 100, 240, 450, 460). Each host proxy among the plurality of host proxies interfaces (110) the host controller to one persistent storage device among a plurality of persistent storage devices within the host device via the storage device proxy. The storage device proxy exposes the plurality of persistent storage devices to the host controller as a single persistent storage device. The encryption core encrypts and decrypts DAR exchanged between the host controller and an encrypted storage device.