In-Line Data-at-Rest Encryption Core for Storage Media

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing out-of-band encryption techniques for Data-at-Rest (DAR) in integrated storage media degrade computing device performance by occupying the host processor and compromising communication paths, leading to reduced throughput and latency.

Innovation Solution

A hardware-based, in-line encryption system that includes an encryption core with a storage device proxy, an encryption engine, and host device proxies, which transparently encrypts data at rest without degrading the host processor's performance by routing data transfer commands based on the encryption state, allowing the host processor to perform other tasks while maintaining encryption integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If out-of-band encryption techniques are used to encrypt Data-at-Rest, then encryption security is provided, but the host processor's availability is reduced and throughput/latency performance degrades

Engineering Contradiction:
Improveencryption securityVSAvoidhost processor availability and throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The encryption functionality is extracted from the host processor and implemented as a separate hardware encryption engine within the storage device. This allows the host processor to offload encryption duties and focus on other computational tasks, thereby improving processor availability and overall system throughput while maintaining encryption security through dedicated hardware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

A communication interface is introduced as an intermediary between the host processor and the encryption engine. This interface handles data transfer and encryption coordination, allowing the host processor to initiate encryption operations without being blocked or occupied during the actual encryption process, thus maintaining high processor availability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate services are used for encrypting Data-at-Rest, then encryption functionality is provided, but communication paths may be compromised and effectiveness reduced

Engineering Contradiction:
Improveencryption effectivenessVSAvoidcommunication path compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The encryption engine is merged into the storage device itself, combining storage and encryption functionalities in a single integrated unit. This eliminates the need for separate communication paths between the host processor and external encryption services, thereby reducing the attack surface and preventing communication path compromises while maintaining encryption effectiveness.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3279824B1Data-at-rest (DAR) encryption for integrated storage media
Publication Date: 2022.01.26 THE BOEING CO
  • EP3279824B1 patent drawingFigure 1~2
  • EP3279824B1 patent drawingFigure 3
  • EP3279824B1 patent drawingFigure 4

AI summary

An improved system (300, 440) for providing transparent, in-line encryption of data-at-rest (DAR) stored by a host controller (220, 420) of a host device (200, 400). An encryption core (320) is instantiated in a hardware device (310) physically coupled to a system board within the host device. The encryption core includes a storage device proxy (330), an encryption engine (340), and a plurality of host device proxies (350A, 350B, 100, 240, 450, 460). Each host proxy among the plurality of host proxies interfaces (110) the host controller to one persistent storage device among a plurality of persistent storage devices within the host device via the storage device proxy. The storage device proxy exposes the plurality of persistent storage devices to the host controller as a single persistent storage device. The encryption core encrypts and decrypts DAR exchanged between the host controller and an encrypted storage device.