Secure Self-Purging Memory Partitions for RPMB Data Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory systems face inefficiencies and increased wear-out when attempting to physically erase cryptographic keys from secure memory partitions, such as Replay Protected Memory Blocks (RPMB), as overwriting logical addresses does not effectively remove data from the original physical location, making frequent purges time-consuming and impractical.
Innovation Solution
Implementing secure self-purging memory partitions with distinct operating parameters for access operations, where data is automatically removed by programming memory cells to a uniform voltage distribution upon logical address overwrite, allowing for efficient and secure erasure without physical purge operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical purge operations are performed to erase cryptographic keys from secure memory partitions, then data security is improved, but time consumption increases and device wear-out increases
Solution Approach 1:
The memory partition performs self-purge operations automatically when logical addresses are overwritten. The system uses distinct operating parameters for access operations versus purge operations, allowing the memory to self-manage its own security without requiring external purge commands from the host system.
Solution Approach 2:
The invention changes the operating parameters of memory cells based on the operation type. During normal access operations, standard read/write parameters are used. When purge operations are triggered by address overwrites, different operating parameters are applied to ensure complete data removal while enabling efficient automated purging.
2Reliability
If frequent purge operations are performed to maintain security, then data security is improved, but device wear-out increases
Solution Approach 1:
The memory partition automatically performs purge operations as part of its normal operation when logical addresses are overwritten. This self-service mechanism eliminates the need for separate manual purge commands from the host system, reducing the frequency of intensive purge operations and thereby decreasing cumulative wear-out while maintaining security.
Solution Approach 2:
The system performs purge operations preliminarily when logical addresses are overwritten, before the memory partition needs to be reused. This preliminary action ensures data is completely removed without requiring subsequent separate purge operations, reducing overall wear-out while maintaining security.
3Ease of operation
If overwriting logical addresses is used to remove data, then ease of operation is improved, but data security deteriorates because original physical location data remains
Solution Approach 1:
The invention applies different operating parameters for access operations versus purge operations. When logical addresses are overwritten, the system changes parameters to trigger a purge operation that completely removes data from the original physical location, thereby maintaining security while preserving the ease of logical address overwriting.
Solution Approach 2:
The system uses feedback from the overwrite operation to automatically trigger purge operations. When a logical address is overwritten, the system detects this event and automatically initiates a purge operation to remove the previous data, creating a feedback loop that maintains security without requiring separate manual purge commands.
Data Source
AI summary
Methods, systems, and devices for secure self-purging memory partitions are described. Systems, techniques and devices are described herein in which data stored in a portion of a secure partition of memory may be removed from the secure partition. In some examples, a portion of secure partition may be allocated as self-purging memory such that data stored therein may be selectively removed in response to a logic address associated with the data being overwritten. In some cases, the data may be removed by programming the memory cells associated with the data to a specific voltage distribution. In some cases, the secure partition may include separate portions having different sets of operating parameters for access operations.


