Memory Encryption Verification Using Host-Stored Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional systems lack the ability to test the encryption function embedded in a memory system from outside.

Innovation Solution

An information processing system comprising a memory system and a host that enables testing of encryption and decryption functions using a verification key stored in the host, allowing verification of encryption and decryption processes from outside the memory system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the encryption function is embedded within the memory system without external access, then the security and integrity of the encryption process are improved, but the ability to verify the encryption function from outside the system deteriorates

Engineering Contradiction:
Improvesecurity of encryption processVSAvoidability to verify encryption function
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a verification key as an intermediary element that enables external verification of the encryption function without compromising the security of the encryption process. The verification key acts as a mediator between the embedded encryption function and external verification systems, allowing the host to verify encryption/decryption operations while the encryption function remains securely embedded within the memory system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent creates a verification copy of the encryption function by implementing a verification mode that replicates encryption/decryption operations using the verification key. This copying mechanism allows external verification of the encryption function's correctness without exposing the actual encryption keys or compromising the security of the primary encryption process.

Inventive Principle:
Principle #26Copying

2Ease of operation

If the verification key is stored in the host rather than the memory system, then the ability to perform external verification is improved, but the security risk of key exposure increases

Engineering Contradiction:
Improveexternal verification capabilityVSAvoidsecurity risk of key exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies local quality by distinguishing between different types of keys with different security requirements. The verification key stored in the host has different security properties than the encryption keys stored in the memory system. The verification key is designed specifically for verification purposes and does not provide the same security risks as exposing actual encryption keys, as it cannot be used to decrypt actual data without the corresponding encryption key.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the key management system into multiple components: encryption keys stored securely in the memory system, verification keys stored in the host, and authentication keys stored in both locations. This segmentation allows different security measures to be applied to different key types, enabling external verification while maintaining the security of the primary encryption process.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12483391B2Information processing system
Publication Date: 2025.11.25 KIOXIA CORP
  • US12483391B2 patent drawing
  • US12483391B2 patent drawing
  • US12483391B2 patent drawing

AI summary

A system encrypts a number by an authentication key to generate first reference data, transmits a result of an authentication process to the host when first encryption data and the first reference data match each other, encrypts or decrypts verification data with a verification key to generate processing data, and transmits the processing data to the host. The host encrypts the number with the authentication key to generate first encryption data, transmits the first encryption data to the memory system, transmits a request regarding an operation in a first mode to the memory system upon reception of a result of the authentication process, transmits the verification key and the verification data read from a second memory to the system, and generates a success notification indicating that an encryptor is working correctly when the processing data and second reference data match each other.