Hierarchical Key Tree for Persistent Memory Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing devices with persistent main memory face security risks due to the continued storage of sensitive data, which can be stolen or corrupted if not properly protected, and existing encryption methods are inefficient, potentially negating the performance benefits of using persistent memory.

Innovation Solution

Incorporating a cryptographic engine with hardware or firmware to encrypt and decrypt data on persistent main memory, using a hierarchical key structure and tree-based key generation information to manage encryption keys, ensuring secure storage and efficient metadata management, and utilizing different keys for various memory regions to enhance security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software programs are used to encrypt and decrypt data on persistent main memory, then security is improved, but processing speed deteriorates significantly

Engineering Contradiction:
Improvedata securityVSAvoidencryption/decryption speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent replaces software-based encryption with hardware-based cryptographic operations. A cryptographic engine is integrated into the memory controller, allowing encryption and decryption to occur in hardware rather than through software programs. This substitution maintains strong security while dramatically improving processing speed, as hardware operations are inherently faster than software execution.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a cryptographic engine as an intermediary component between the memory controller and persistent main memory. This intermediary handles all encryption and decryption operations, shielding the main processing system from security-critical operations while maintaining high-speed data access. The cryptographic engine acts as a dedicated security layer that does not bottleneck overall system performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple different keys are used for various memory regions, then security is enhanced, but key management complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides persistent main memory into multiple encrypted regions, each protected by a unique encryption key. This segmentation allows different security policies to be applied to different memory areas (e.g., secure boot region, user data region, system region). The memory controller automatically manages which key applies to which region, reducing the manual management burden while maintaining enhanced security through regional isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a hierarchical key structure where a master key or root key can derive multiple regional keys. This nested approach allows secure storage of multiple keys by nesting them within a unified key hierarchy. The cryptographic engine automatically traverses this nested structure to retrieve appropriate keys for each memory region, simplifying key management while maintaining the security benefits of multiple keys.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Productivity

If persistent main memory is used to store both transient and persistent data, then performance is improved by eliminating data transfer between secondary storage and main memory, but security risks increase due to continued storage of sensitive data

Engineering Contradiction:
Improvesystem performanceVSAvoidsecurity risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security measures to different portions of persistent main memory based on their sensitivity requirements. Critical system data and transient data receive different encryption treatments than user data or persistent storage data. This localized security approach allows the system to maintain high performance by keeping frequently accessed data in persistent memory while applying appropriate security controls only where needed, rather than uniformly securing entire memory spaces.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3185464B1Key generation information trees
Publication Date: 2020.05.20 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • EP3185464B1 patent drawingFigure 1
  • EP3185464B1 patent drawingFigure 2
  • EP3185464B1 patent drawingFigure 3

AI summary

An example non-transitory computer-readable medium includes instructions that, when executed by a processor, cause the processor to receive a request for data. The instructions also cause the processor to determine a region containing the data based on the metadata. The instructions cause the processor to traverse a tree in the metadata to determine key generation information relating a decryption key for the region to a root key.