Memory Subsystem Key Encryption for Secure Retention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Memory sub-systems face security risks due to the inability to retain cryptographic keys when power is lost, and storing these keys in nonvolatile memory devices makes them accessible to third parties or firmware, compromising data security.

Innovation Solution

Encrypting cryptographic keys before storing them in nonvolatile memory devices, using a second cryptographic key and initialization vector, and storing error correction information to ensure key integrity and security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If cryptographic keys are stored in nonvolatile memory devices, then data can be retained after power loss, but security is compromised because third parties or firmware can access the keys

Engineering Contradiction:
Improvekey retentionVSAvoidunauthorized access
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary encryption of cryptographic keys before storing them in nonvolatile memory. The encryption operation is completed in advance, transforming plain keys into encrypted form that cannot be accessed by third parties or firmware, while still allowing legitimate decryption when needed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

An encrypted form of cryptographic keys serves as an intermediary between the need for key retention and security requirements. The encrypted keys stored in nonvolatile memory act as a secure representation that preserves key functionality while blocking unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If cryptographic keys are stored in volatile memory, then security is maintained against third-party access, but keys are lost when power is lost

Engineering Contradiction:
Improveunauthorized accessVSAvoidkey retention
Core Design Contradiction:
Object-affected harmful factorsVSDuration of action of stationary object

Solution Approach 1:

The system performs preliminary encryption of cryptographic keys before storing them in nonvolatile memory. The encryption operation is completed in advance, transforming plain keys into encrypted form that cannot be accessed by third parties or firmware, while still allowing legitimate decryption when needed.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If cryptographic keys are encrypted before storage, then security is enhanced, but additional processing steps are required

Engineering Contradiction:
Improveunauthorized accessVSAvoidkey management process
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The system implements self-service through automated encryption and decryption operations. The controller automatically encrypts keys before storage and decrypts them when needed, eliminating the need for manual key management intervention while maintaining enhanced security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11615214B2Cryptographic key management
Publication Date: 2023.03.28 MICRON TECHNOLOGY INC
  • US11615214B2 patent drawing
  • US11615214B2 patent drawing
  • US11615214B2 patent drawing

AI summary

Methods, systems, and devices for cryptographic key management are described. A memory device can issue, by a firmware component, a command to generate a first cryptographic key for encrypting or decrypting user data stored on a memory device. The memory device can generate, by a hardware component, the first cryptographic key based on the command. The memory device can encrypt, by the hardware component, the first cryptographic key using a second cryptographic key and an initialization vector. The memory device can store the encrypted first cryptographic key in a nonvolatile memory device separate from the hardware component.