Memory Module Encryption Key Storage Circuit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Memory modules in data centers are vulnerable to data leakage, as demonstrated by attempts to extract data by freezing modules with liquefied nitrogen, highlighting the need for enhanced security measures to prevent unauthorized access and data theft.
Innovation Solution
Implementing a memory system with encryption key storage circuits in each memory module that generate and use unique encryption keys to encrypt addresses and data, ensuring that only authorized access can retrieve stored information, thereby preventing data leakage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is stored in memory modules without encryption, then data accessibility and operation speed are maintained, but data security and protection against unauthorized access are compromised
Solution Approach 1:
The memory system is segmented into multiple independent memory devices, each with its own encryption key storage circuit and encryption key. This segmentation allows each memory device to operate independently with unique security credentials, enhancing overall system security while maintaining modular architecture that limits the impact of complexity to individual units rather than the entire system.
Solution Approach 2:
Encryption keys are pre-loaded into the encryption key storage circuits during manufacturing or initialization before the memory devices are deployed. This preliminary action ensures that security credentials are already in place before data storage operations begin, eliminating the need for complex runtime key management and reducing operational complexity.
2Object-affected harmful factors
If encryption keys are stored in each memory device, then data protection against physical extraction is improved, but the complexity of key management and storage increases
Solution Approach 1:
Each memory device is equipped with its own local encryption key storage circuit and unique encryption key, creating localized security credentials specific to each device. This local quality approach ensures that even if one memory device is compromised, other devices remain protected by their own unique keys, preventing system-wide security failure while maintaining manageable key scope at the device level.
Solution Approach 2:
The encryption key storage circuit acts as an intermediary between the external environment and the sensitive data stored in the memory device. This intermediary component isolates the encryption keys from direct external access, requiring authorized commands and procedures to retrieve or use the keys, thereby preventing direct extraction while maintaining controlled access management.
3Reliability
If addresses are encrypted before accessing memory cells, then unauthorized access to specific data locations is prevented, but the speed of address translation and memory access may be reduced
Solution Approach 1:
The encryption and decryption operations are implemented using electronic circuitry within the memory device, replacing what would otherwise be external software-based encryption processes. This substitution of mechanical/software operations with dedicated electronic hardware circuits significantly reduces the time required for address translation, maintaining memory access speeds close to traditional systems while providing strong access authorization control.
Data Source
AI summary
A memory module includes: a plurality of memories, wherein each of the memories comprises: an encryption key storage circuit suitable for storing an encryption key; an address encryption circuit suitable for generating an encrypted address by encrypting an address transferred from a memory controller by using the encryption key stored in the encryption key storage circuit; and a cell array accessed by the encrypted address, wherein the encryption key storage circuits of the memories store different encryption keys.


