Storage Class Memory Migration via Intermediary Key Decryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current information handling systems face challenges in securely migrating and decrypting encrypted data stored in storage class memories across different information handling systems, particularly due to variations in encryption keys and trust chain management.
Innovation Solution
The system receives a public encryption key from a second information handling system, decrypts encrypted symmetric encryption keys using asymmetric cryptography, and physically transfers a memory device with both volatile and non-volatile media, allowing decryption of data using symmetric encryption keys associated with specific address ranges, thereby establishing a trust chain and verifying component migrations through baseboard management controllers and cluster managers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If encrypted data is migrated from one information handling system to another, then data portability and system flexibility are improved, but key management complexity and security risks increase
Solution Approach 1:
The patent introduces a memory encryption key (MEK) as an intermediary that bridges the data and the decryption process. The MEK is stored in a protected area of the memory device and is used to decrypt data regardless of which information handling system the data is migrated to, thereby simplifying key management while maintaining data portability
Solution Approach 2:
The encryption key management is segmented into multiple components: the original data encryption keys, the memory encryption key (MEK) stored in protected memory, and the association between keys and memory address ranges. This segmentation allows the system to migrate data without migrating all keys, reducing key management complexity
2Reliability
If data is encrypted with different encryption keys in different information handling systems, then system-specific security is improved, but data migration and interoperability deteriorate
Solution Approach 1:
The patent performs preliminary encryption of data using the MEK before data migration occurs. The MEK is pre-stored in a protected area of the memory device, and data is pre-encrypted with this key. This preliminary action ensures that when data is migrated to a different information handling system, the same MEK can decrypt the data, enabling interoperability while maintaining security
Solution Approach 2:
The patent changes the encryption parameter from system-specific keys to a memory-device-specific MEK. By using the MEK that is tied to the memory device rather than the information handling system, the encryption scheme becomes portable across different systems, improving data migration capability while maintaining security through the protected storage of the MEK
3Productivity
If symmetric encryption keys are used for data encryption, then encryption efficiency is improved, but key distribution and management difficulty increase
Solution Approach 1:
The memory device serves itself by storing the MEK in a protected area and using it to encrypt and decrypt data without requiring external key distribution. The MEK remains within the memory device, eliminating the need for complex key distribution infrastructure while maintaining efficient symmetric encryption, thereby improving both encryption efficiency and key distribution ease
Data Source
AI summary
A Computing environment is described to enable an information handling system (IHS) to receive a public encryption key from another IHS; and decrypt with a public encryption key one or more encrypted symmetric encryption keys, encrypted via a private encryption key, to obtain one or more symmetric encryption keys respectively associated with one or more memory address ranges. The IHS may physically receive a memory device that was utilized by the other IHS to store information in an encrypted fashion. The IHS may further decrypt, with a first encryption key of the one or more symmetric encryption keys associated with a first address range of the one or more address ranges, first encrypted data stored by the at least one non-volatile memory medium to obtain first data.


