Memory Subsystem Key Encryption for Secure Retention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Memory sub-systems face security risks due to the inability to retain cryptographic keys when power is lost, and storing these keys in nonvolatile memory devices makes them accessible to third parties or firmware, compromising data security.
Innovation Solution
Encrypting cryptographic keys before storing them in nonvolatile memory devices, using a second cryptographic key and initialization vector, and storing error correction information to ensure key integrity and security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Duration of action of stationary object
If cryptographic keys are stored in nonvolatile memory devices, then data can be retained after power loss, but security is compromised because third parties or firmware can access the keys
Solution Approach 1:
The system performs preliminary encryption of cryptographic keys before storing them in nonvolatile memory. The encryption operation is completed in advance, transforming plain keys into encrypted form that cannot be accessed by third parties or firmware, while still allowing legitimate decryption when needed.
Solution Approach 2:
An encrypted form of cryptographic keys serves as an intermediary between the need for key retention and security requirements. The encrypted keys stored in nonvolatile memory act as a secure representation that preserves key functionality while blocking unauthorized access.
2Object-affected harmful factors
If cryptographic keys are stored in volatile memory, then security is maintained against third-party access, but keys are lost when power is lost
Solution Approach 1:
The system performs preliminary encryption of cryptographic keys before storing them in nonvolatile memory. The encryption operation is completed in advance, transforming plain keys into encrypted form that cannot be accessed by third parties or firmware, while still allowing legitimate decryption when needed.
3Object-affected harmful factors
If cryptographic keys are encrypted before storage, then security is enhanced, but additional processing steps are required
Solution Approach 1:
The system implements self-service through automated encryption and decryption operations. The controller automatically encrypts keys before storage and decrypts them when needed, eliminating the need for manual key management intervention while maintaining enhanced security.
Data Source
AI summary
Methods, systems, and devices for cryptographic key management are described. A memory device can issue, by a firmware component, a command to generate a first cryptographic key for encrypting or decrypting user data stored on a memory device. The memory device can generate, by a hardware component, the first cryptographic key based on the command. The memory device can encrypt, by the hardware component, the first cryptographic key using a second cryptographic key and an initialization vector. The memory device can store the encrypted first cryptographic key in a nonvolatile memory device separate from the hardware component.


