Memory Encryption Verification Using Host-Stored Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional systems lack the ability to test the encryption function embedded in a memory system from outside.
Innovation Solution
An information processing system comprising a memory system and a host that enables testing of encryption and decryption functions using a verification key stored in the host, allowing verification of encryption and decryption processes from outside the memory system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the encryption function is embedded within the memory system without external access, then the security and integrity of the encryption process are improved, but the ability to verify the encryption function from outside the system deteriorates
Solution Approach 1:
The patent introduces a verification key as an intermediary element that enables external verification of the encryption function without compromising the security of the encryption process. The verification key acts as a mediator between the embedded encryption function and external verification systems, allowing the host to verify encryption/decryption operations while the encryption function remains securely embedded within the memory system.
Solution Approach 2:
The patent creates a verification copy of the encryption function by implementing a verification mode that replicates encryption/decryption operations using the verification key. This copying mechanism allows external verification of the encryption function's correctness without exposing the actual encryption keys or compromising the security of the primary encryption process.
2Ease of operation
If the verification key is stored in the host rather than the memory system, then the ability to perform external verification is improved, but the security risk of key exposure increases
Solution Approach 1:
The patent applies local quality by distinguishing between different types of keys with different security requirements. The verification key stored in the host has different security properties than the encryption keys stored in the memory system. The verification key is designed specifically for verification purposes and does not provide the same security risks as exposing actual encryption keys, as it cannot be used to decrypt actual data without the corresponding encryption key.
Solution Approach 2:
The patent segments the key management system into multiple components: encryption keys stored securely in the memory system, verification keys stored in the host, and authentication keys stored in both locations. This segmentation allows different security measures to be applied to different key types, enabling external verification while maintaining the security of the primary encryption process.
Data Source
AI summary
A system encrypts a number by an authentication key to generate first reference data, transmits a result of an authentication process to the host when first encryption data and the first reference data match each other, encrypts or decrypts verification data with a verification key to generate processing data, and transmits the processing data to the host. The host encrypts the number with the authentication key to generate first encryption data, transmits the first encryption data to the memory system, transmits a request regarding an operation in a first mode to the memory system upon reception of a result of the authentication process, transmits the verification key and the verification data read from a second memory to the system, and generates a success notification indicating that an encryptor is working correctly when the processing data and second reference data match each other.


