MRAM Key Storage for Rapid Data Sanitization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face challenges in quickly and efficiently preventing access to sensitive data, especially when being moved or when the system becomes inoperable, due to the time-consuming nature of secure erase operations and difficulties in securing data in failed systems.

Innovation Solution

A security mechanism utilizing a magnetoresistive random access memory (MRAM) module to store and manage encryption keys, allowing for transparent encryption and decryption of data, and enabling rapid erasure of the encryption key by a magnetic field, thus preventing access without modifying the stored data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional secure erase operations are performed to prevent access to stored data, then data security is improved, but the time required for the operation increases significantly (2-3 days for large capacity systems)

Engineering Contradiction:
Improvedata securityVSAvoidsecure erase operation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The invention extracts the encryption key from the storage system and stores it separately in an MRAM module. When security erasure is needed, only the small MRAM module containing the key needs to be erased, not the entire large-capacity storage system. This extraction approach reduces the erase operation time from days to seconds while maintaining data security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention changes the physical state or properties of the storage medium by using MRAM (magnetoresistive random access memory) with different erasure characteristics compared to traditional storage media. MRAM can be rapidly erased by applying a magnetic field, changing the erasure time parameter from 2-3 days to seconds, while the encrypted data remains intact on the main storage system.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If data is stored in a data storage system for later retrieval, then data accessibility is improved, but vulnerability to unauthorized access increases when the system is moved or fails

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The invention introduces an intermediary security layer using separate encryption key storage in MRAM. The encrypted data on the main storage system is protected by this intermediary key, which must be present and accessible for decryption. This intermediary mechanism enables normal data accessibility during operation while preventing unauthorized access when the system is moved or fails, as the key can be rapidly erased in those scenarios.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If encryption keys are stored in the same location as encrypted data, then system simplicity is improved, but security is worsened when the system becomes inoperable or is moved

Engineering Contradiction:
Improvesystem structureVSAvoidsecurity maintenance
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The invention segments the security-critical component (encryption key) from the main storage system by using a separate MRAM module. This segmentation allows the key to be independently managed and rapidly erased when needed, improving security maintenance capability without significantly increasing overall system complexity. The MRAM module can be integrated into the existing storage system architecture with minimal additional components.

Inventive Principle:
Principle #1Segmentation

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides a quick, efficient, and operator-friendly method to sanitize data storage systems, ensuring access is prevented even when the system is nonfunctional, significantly reducing the time required compared to traditional methods.

Implementation Method 1

A security mechanism utilizing a magnetoresistive random access memory (MRAM) module to store and manage encryption keys

Methodology Applied
Scientific EffectMagnetoresistive random access memory (MRAM): Magnetoresistance

Implementation Method 2

enabling rapid erasure of the encryption key by a magnetic field, thus preventing access without modifying the stored data

Methodology Applied
Scientific EffectMagnetic field erasure: Magnetic Field

Data Source

PatentUS8909942B1MRAM-based security for data storage systems
Publication Date: 2014.12.09 WESTERN DIGITAL TECHNOLOGIES INC
  • US8909942B1 patent drawing
  • US8909942B1 patent drawing
  • US8909942B1 patent drawing

AI summary

A secure data storage system includes a mechanism that can be activated to inhibit access to stored data. In one embodiment, access to stored data can be prevented without having to erase or modify such data. An encryption key, or data used to generate the encryption key, is stored in an MRAM module integrated within the data storage system. The data storage system uses the encryption key to encrypt data received from a host system, and to decrypt the encrypted data when it is subsequently read by a host system. To render the stored data inaccessible, an operator (or an automated process) can expose the MRAM module to a magnetic field of sufficient strength to erase key data therefrom.