Non-Volatile Memory Key Destruction for Secure Data Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current secure data erasure methods face challenges in ensuring the secure destruction of encryption keys, especially when storage devices are damaged and require repair outside a secure facility, as existing techniques may not effectively protect against unauthorized access or data recovery.
Innovation Solution
The implementation of a system that enables the electrical destruction of cryptographic key material retained in non-volatile memory, even when the storage device is inoperable, using an eraser device that provides power and commands to zeroize or destroy the key material, ensuring secure erasure through an external interface or physical removal of key information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption keys are stored in non-volatile memory for data protection, then data security is improved, but the risk of unauthorized key access increases when the storage device is damaged or repaired outside a secure facility
Solution Approach 1:
The patent extracts the cryptographic key material from the main storage device memory and stores it separately in a dedicated non-volatile memory component. This separation allows the key material to be securely destroyed independently of the storage device, preventing unauthorized access during repair or transport while maintaining data security through isolated key protection.
Solution Approach 2:
The patent implements preliminary destruction of cryptographic key material before the storage device leaves a secure facility for repair or transport. By proactively destroying the keys in advance, the system prevents potential unauthorized access that could occur if the device were compromised during external handling, thereby maintaining data security without requiring the device to remain in a secure environment.
2Reliability
If cryptographic key material is destroyed in a non-operational storage device, then secure data erasure is achieved, but the complexity of the destruction process increases
Solution Approach 1:
The patent enables the non-volatile memory component to autonomously destroy its own cryptographic key material through electrical destruction methods. The memory component includes circuitry that can self-destruct the stored key material when triggered, eliminating the need for complex external destruction equipment and simplifying the overall process while ensuring secure data erasure.
Solution Approach 2:
The patent replaces complex mechanical or physical destruction methods with electrical destruction techniques. By using electrical signals to destroy the cryptographic key material in the non-volatile memory, the system achieves secure data erasure through a simpler, more controllable electrical process rather than requiring complex mechanical disassembly or physical destruction of the storage device.
3Adaptability or versatility
If an external eraser device is used to destroy cryptographic keys, then key destruction capability is improved, but the requirement for external equipment increases system complexity
Solution Approach 1:
The patent merges the key destruction capability directly into the non-volatile memory component itself, combining the storage and destruction functions in a single integrated component. This eliminates the need for separate external eraser devices while maintaining the ability to securely destroy cryptographic keys, thereby reducing system complexity while preserving adaptability for key destruction.
Data Source
AI summary
Techniques for encryption key destruction for secure data erasure via an external interface or physical key removal are described. Electrical destruction of key material retained in a memory of a storage device renders the device securely erased, even when the device is otherwise inoperable. The memory (e.g. non-volatile, such as flash) stores key material for encrypting/decrypting storage data for the device. An eraser provides power and commands to the memory, even when all or any portion of the device is inoperable. The commands (e.g. erase or write) enable zeroizing or destroying the key material, rendering data encrypted with the destroyed key material inaccessible, and therefore securely erased. Alternatively, the memory is a removable component (e.g. an external security device or smartcard) coupled to the device during storage operation. Removing and physically destroying the memory renders the device securely erased. The device and/or the memory are sealed to enable tamper detection.


