Memory Controller Ownership Identifiers for Encrypted Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices with virtual machines and hypervisors face challenges in protecting encrypted data from malicious entities, as encrypted data can still reveal information about virtual machine operations even when not decrypted, and legacy virtual machines may not support advanced security features, leading to potential errors and inefficiencies.
Innovation Solution
Implementing a system where ownership identifiers are stored in metadata with encrypted data, allowing the controller circuitry to determine whether to return encrypted data or substitute data based on the requesting entity's type, thereby preventing unauthorized access and maintaining security without relying on unsupported features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encrypted data is stored in memory, then data confidentiality is improved, but information leakage about virtual machine operations may occur
Solution Approach 1:
The patent creates substitute data that copies the structural and metadata characteristics of encrypted data without containing the actual confidential information. When a supporting virtual machine's data is accessed by an unauthorized entity, the system returns substitute data with matching size, timing, and metadata patterns, preventing information leakage while maintaining operational appearance.
Solution Approach 2:
The patent introduces controller circuitry as an intermediary between memory and accessing entities. This intermediary intercepts access requests, verifies authorization, and selectively returns either encrypted data or substitute data based on the requester's credentials, thereby preventing direct access to confidential information while maintaining system functionality.
2Reliability
If advanced security features are implemented for supporting virtual machines, then data protection is improved, but legacy virtual machines may experience errors due to unsupported features
Solution Approach 1:
The patent applies different data return strategies based on the requester's type. Supporting virtual machines with proper authorization receive encrypted data with full security features, while legacy or unauthorized entities receive substitute data with basic characteristics. This localized approach allows advanced security features to protect authorized access without causing errors in legacy systems.
Solution Approach 2:
The patent changes the data return parameter based on authorization status. For unauthorized access attempts, the system transforms the response from actual encrypted data to substitute data with matching metadata parameters (size, timing, format) but different content parameters. This allows legacy virtual machines to operate without errors while maintaining security for authorized entities.
3Measurement precision
If ownership identifiers are stored in metadata, then access control precision is improved, but memory overhead increases
Solution Approach 1:
The patent makes the ownership identifier field in memory metadata serve multiple functions: it identifies data ownership for access control decisions, enables the controller to determine whether to return encrypted data or substitute data, and provides auditing information. This multi-functionality achieves precise access control without requiring separate dedicated storage structures.
Solution Approach 2:
The patent merges the ownership identification function with the existing metadata structure that already accompanies encrypted data in memory. By combining ownership identifiers with existing metadata fields rather than creating separate storage mechanisms, the system achieves precise access control while minimizing additional memory overhead.
Data Source
AI summary
An electronic device includes a memory and controller circuitry. The controller circuitry, responsive to a read request to read encrypted data stored in the memory, acquires, from metadata stored with the encrypted data in the memory, an ownership identifier identifying a type of writing entity that stored the encrypted data in the memory. The controller circuitry uses the ownership identifier to control whether, when responding to the read request, data decrypted from the encrypted data is returned or substitute data is returned instead of data decrypted from the encrypted data.


