MRAM Key Storage for Rapid Data Sanitization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face challenges in quickly and efficiently preventing access to sensitive data, especially when being moved or when the system becomes inoperable, due to the time-consuming nature of secure erase operations and difficulties in securing data in failed systems.
Innovation Solution
A security mechanism utilizing a magnetoresistive random access memory (MRAM) module to store and manage encryption keys, allowing for transparent encryption and decryption of data, and enabling rapid erasure of the encryption key by a magnetic field, thus preventing access without modifying the stored data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional secure erase operations are performed to prevent access to stored data, then data security is improved, but the time required for the operation increases significantly (2-3 days for large capacity systems)
Solution Approach 1:
The invention extracts the encryption key from the storage system and stores it separately in an MRAM module. When security erasure is needed, only the small MRAM module containing the key needs to be erased, not the entire large-capacity storage system. This extraction approach reduces the erase operation time from days to seconds while maintaining data security.
Solution Approach 2:
The invention changes the physical state or properties of the storage medium by using MRAM (magnetoresistive random access memory) with different erasure characteristics compared to traditional storage media. MRAM can be rapidly erased by applying a magnetic field, changing the erasure time parameter from 2-3 days to seconds, while the encrypted data remains intact on the main storage system.
2Ease of operation
If data is stored in a data storage system for later retrieval, then data accessibility is improved, but vulnerability to unauthorized access increases when the system is moved or fails
Solution Approach 1:
The invention introduces an intermediary security layer using separate encryption key storage in MRAM. The encrypted data on the main storage system is protected by this intermediary key, which must be present and accessible for decryption. This intermediary mechanism enables normal data accessibility during operation while preventing unauthorized access when the system is moved or fails, as the key can be rapidly erased in those scenarios.
3Device complexity
If encryption keys are stored in the same location as encrypted data, then system simplicity is improved, but security is worsened when the system becomes inoperable or is moved
Solution Approach 1:
The invention segments the security-critical component (encryption key) from the main storage system by using a separate MRAM module. This segmentation allows the key to be independently managed and rapidly erased when needed, improving security maintenance capability without significantly increasing overall system complexity. The MRAM module can be integrated into the existing storage system architecture with minimal additional components.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution provides a quick, efficient, and operator-friendly method to sanitize data storage systems, ensuring access is prevented even when the system is nonfunctional, significantly reducing the time required compared to traditional methods.
Implementation Method 1
A security mechanism utilizing a magnetoresistive random access memory (MRAM) module to store and manage encryption keys
Implementation Method 2
enabling rapid erasure of the encryption key by a magnetic field, thus preventing access without modifying the stored data
Data Source
AI summary
A secure data storage system includes a mechanism that can be activated to inhibit access to stored data. In one embodiment, access to stored data can be prevented without having to erase or modify such data. An encryption key, or data used to generate the encryption key, is stored in an MRAM module integrated within the data storage system. The data storage system uses the encryption key to encrypt data received from a host system, and to decrypt the encrypted data when it is subsequently read by a host system. To render the stored data inaccessible, an operator (or an automated process) can expose the MRAM module to a magnetic field of sufficient strength to erase key data therefrom.


