Storage Class Memory Migration via Intermediary Key Decryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in securely migrating and decrypting encrypted data stored in storage class memories across different information handling systems, particularly due to variations in encryption keys and trust chain management.

Innovation Solution

The system receives a public encryption key from a second information handling system, decrypts encrypted symmetric encryption keys using asymmetric cryptography, and physically transfers a memory device with both volatile and non-volatile media, allowing decryption of data using symmetric encryption keys associated with specific address ranges, thereby establishing a trust chain and verifying component migrations through baseboard management controllers and cluster managers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If encrypted data is migrated from one information handling system to another, then data portability and system flexibility are improved, but key management complexity and security risks increase

Engineering Contradiction:
Improvedata portabilityVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a memory encryption key (MEK) as an intermediary that bridges the data and the decryption process. The MEK is stored in a protected area of the memory device and is used to decrypt data regardless of which information handling system the data is migrated to, thereby simplifying key management while maintaining data portability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The encryption key management is segmented into multiple components: the original data encryption keys, the memory encryption key (MEK) stored in protected memory, and the association between keys and memory address ranges. This segmentation allows the system to migrate data without migrating all keys, reducing key management complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If data is encrypted with different encryption keys in different information handling systems, then system-specific security is improved, but data migration and interoperability deteriorate

Engineering Contradiction:
Improvesystem-specific securityVSAvoiddata migration capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary encryption of data using the MEK before data migration occurs. The MEK is pre-stored in a protected area of the memory device, and data is pre-encrypted with this key. This preliminary action ensures that when data is migrated to a different information handling system, the same MEK can decrypt the data, enabling interoperability while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the encryption parameter from system-specific keys to a memory-device-specific MEK. By using the MEK that is tied to the memory device rather than the information handling system, the encryption scheme becomes portable across different systems, improving data migration capability while maintaining security through the protected storage of the MEK

Inventive Principle:
Principle #35Parameter changes

3Productivity

If symmetric encryption keys are used for data encryption, then encryption efficiency is improved, but key distribution and management difficulty increase

Engineering Contradiction:
Improveencryption efficiencyVSAvoidkey distribution ease
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The memory device serves itself by storing the MEK in a protected area and using it to encrypt and decrypt data without requiring external key distribution. The MEK remains within the memory device, eliminating the need for complex key distribution infrastructure while maintaining efficient symmetric encryption, thereby improving both encryption efficiency and key distribution ease

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11595192B2System and method of migrating one or more storage class memories from a first information handling system to a second information handling system
Publication Date: 2023.02.28 DELL PROD LP
  • US11595192B2 patent drawing
  • US11595192B2 patent drawing
  • US11595192B2 patent drawing

AI summary

A Computing environment is described to enable an information handling system (IHS) to receive a public encryption key from another IHS; and decrypt with a public encryption key one or more encrypted symmetric encryption keys, encrypted via a private encryption key, to obtain one or more symmetric encryption keys respectively associated with one or more memory address ranges. The IHS may physically receive a memory device that was utilized by the other IHS to store information in an encrypted fashion. The IHS may further decrypt, with a first encryption key of the one or more symmetric encryption keys associated with a first address range of the one or more address ranges, first encrypted data stored by the at least one non-volatile memory medium to obtain first data.