Hierarchical Key Tree for Persistent Memory Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing devices with persistent main memory face security risks due to the continued storage of sensitive data, which can be stolen or corrupted if not properly protected, and existing encryption methods are inefficient, potentially negating the performance benefits of using persistent memory.
Innovation Solution
Incorporating a cryptographic engine with hardware or firmware to encrypt and decrypt data on persistent main memory, using a hierarchical key structure and tree-based key generation information to manage encryption keys, ensuring secure storage and efficient metadata management, and utilizing different keys for various memory regions to enhance security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If software programs are used to encrypt and decrypt data on persistent main memory, then security is improved, but processing speed deteriorates significantly
Solution Approach 1:
The patent replaces software-based encryption with hardware-based cryptographic operations. A cryptographic engine is integrated into the memory controller, allowing encryption and decryption to occur in hardware rather than through software programs. This substitution maintains strong security while dramatically improving processing speed, as hardware operations are inherently faster than software execution.
Solution Approach 2:
The patent introduces a cryptographic engine as an intermediary component between the memory controller and persistent main memory. This intermediary handles all encryption and decryption operations, shielding the main processing system from security-critical operations while maintaining high-speed data access. The cryptographic engine acts as a dedicated security layer that does not bottleneck overall system performance.
2Reliability
If multiple different keys are used for various memory regions, then security is enhanced, but key management complexity increases
Solution Approach 1:
The patent divides persistent main memory into multiple encrypted regions, each protected by a unique encryption key. This segmentation allows different security policies to be applied to different memory areas (e.g., secure boot region, user data region, system region). The memory controller automatically manages which key applies to which region, reducing the manual management burden while maintaining enhanced security through regional isolation.
Solution Approach 2:
The patent implements a hierarchical key structure where a master key or root key can derive multiple regional keys. This nested approach allows secure storage of multiple keys by nesting them within a unified key hierarchy. The cryptographic engine automatically traverses this nested structure to retrieve appropriate keys for each memory region, simplifying key management while maintaining the security benefits of multiple keys.
3Productivity
If persistent main memory is used to store both transient and persistent data, then performance is improved by eliminating data transfer between secondary storage and main memory, but security risks increase due to continued storage of sensitive data
Solution Approach 1:
The patent applies different security measures to different portions of persistent main memory based on their sensitivity requirements. Critical system data and transient data receive different encryption treatments than user data or persistent storage data. This localized security approach allows the system to maintain high performance by keeping frequently accessed data in persistent memory while applying appropriate security controls only where needed, rather than uniformly securing entire memory spaces.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An example non-transitory computer-readable medium includes instructions that, when executed by a processor, cause the processor to receive a request for data. The instructions also cause the processor to determine a region containing the data based on the metadata. The instructions cause the processor to traverse a tree in the metadata to determine key generation information relating a decryption key for the region to a root key.