Memory Controller Key Cache for Faster Nonvolatile Data Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing non-volatile memory systems face inefficiencies due to the requirement of a large-capacity volatile memory for storing encryption keys, leading to increased costs and performance degradation in data encryption and decryption processes.
Innovation Solution
Implementing a host memory buffer (HMB) to store encryption keys, utilizing a key cache to enhance key retrieval speed, and employing multiple encryption and decryption portions within the memory controller to manage keys efficiently.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a large-capacity volatile memory is provided in the non-volatile memory system to store encryption keys according to the KPIO standard, then the security and encryption capability is improved, but the system cost increases and performance degrades due to longer key access time
Solution Approach 1:
The patent extracts the key storage function from the memory controller's volatile memory and relocates it to the host's volatile memory buffer. The memory controller only retains a small key cache for frequently accessed keys, while the host manages the large key storage space. This extraction resolves the contradiction by eliminating the need for large volatile memory in the memory system while maintaining encryption security through host-managed key storage.
Solution Approach 2:
The patent introduces a key cache in the memory controller as an intermediary between the host's key storage and the encryption/decryption operations. The key cache stores frequently accessed keys locally, enabling fast access for common operations while the host's volatile memory buffer provides the complete key repository. This intermediary structure resolves the speed-security tradeoff by providing both fast local access and comprehensive key management.
2Adaptability or versatility
If a large-capacity volatile memory is provided in the non-volatile memory system to store encryption keys, then the key management capability is improved, but the system complexity and manufacturing cost increase
Solution Approach 1:
The patent extracts the large-capacity volatile memory component from the memory system and relocates it to the host system. The memory controller is simplified to contain only essential components (processor, buffer memory, and small key cache), while the host assumes responsibility for storing the complete set of encryption keys in its volatile memory buffer. This extraction reduces memory system complexity and manufacturing cost while preserving full key management capability through host involvement.
Solution Approach 2:
The patent makes the host's volatile memory buffer serve multiple functions: it acts as the general-purpose memory buffer for data operations and simultaneously serves as the key storage repository for encryption operations. This multi-functionality eliminates the need for dedicated large-capacity volatile memory in the memory system, reducing overall system complexity while maintaining comprehensive key management capabilities.
3Quantity of substance
If DRAM is used as memory for storing encryption keys, then the key storage capacity is improved, but the key access time increases resulting in performance degradation
Solution Approach 1:
The patent segments the key storage system into two parts: a small key cache in the memory controller's buffer memory for frequently accessed keys, and a large key repository in the host's volatile memory buffer. This segmentation allows the system to maintain large overall key storage capacity while providing fast access for commonly used keys through the local cache, thereby resolving the capacity-speed tradeoff.
Solution Approach 2:
The patent applies local quality by providing different storage characteristics for different keys based on their access patterns. Frequently accessed keys are cached in the memory controller's buffer memory for immediate local access, while less frequently accessed keys are stored in the host's volatile memory buffer. This differentiated approach optimizes access time for critical operations while maintaining overall large key storage capacity.
Data Source
AI summary
The present disclosure relates to a memory system capable of encrypting and storing data, and a memory controller. The memory controller may include a first interface configured to perform data communication with a first external device, a second interface configured to generate a signal for controlling an operation of a second external device and transmit the signal; and a processor configured to receive, from the first external device, a data write command to write data to the second external device, encrypt the data by using one of a plurality of keys stored in a key area provided in the first external device in response to the data write command, and then control the encrypted data to be written to the second external device.


