Storage Controller Dual Encryption with Homomorphic Data Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large-scale data operations between a central processing unit (CPU) and a storage device are slowed by data transfer speeds, and existing storage devices lack efficient methods to encrypt data for security while maintaining computational performance.
Innovation Solution
The storage device incorporates dual encryption circuits using a homomorphic encryption algorithm and a symmetric or asymmetric key algorithm to selectively encrypt data based on command fields, allowing computations on encrypted data and improving data security and transfer speeds.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is encrypted using traditional methods before storage, then data security is improved, but data transfer speed and computational performance deteriorate
Solution Approach 1:
The patent changes the fundamental parameter of encryption by using homomorphic encryption algorithms that allow computations to be performed directly on encrypted data. This eliminates the need to decrypt data before processing, thereby maintaining data security while enabling fast computational operations on the encrypted data itself, resolving the contradiction between security and speed
Solution Approach 2:
The patent introduces an intermediary encryption circuit within the storage device that performs homomorphic encryption operations. This intermediary component enables computational processing of encrypted data without requiring the data to leave the encrypted state, thus maintaining security while enabling efficient computation and transfer
2Reliability
If data is encrypted to ensure security, then data security is improved, but computational performance on the data deteriorates
Solution Approach 1:
The patent fundamentally changes the encryption parameter from traditional symmetric/asymmetric encryption to homomorphic encryption, which has the unique property of allowing mathematical operations to be performed on encrypted data. This enables the storage device to perform computational operations directly on encrypted data, maintaining security while achieving productive computational processing without decryption
Solution Approach 2:
The encrypted data itself becomes self-sufficient for computational operations through homomorphic encryption. The data in encrypted form can undergo computational processing without external intervention to decrypt it first, allowing the storage device to autonomously perform computations on secure data, thus maintaining both security and computational productivity
3Productivity
If large-scale data operations are performed between CPU and storage device, then data processing capability is improved, but data transfer speed deteriorates
Solution Approach 1:
The patent merges the encryption function into the storage device itself through an integrated encryption circuit. This combination eliminates the need for separate encryption/decryption steps that would require additional data transfer between CPU and storage device, allowing large-scale data operations to be performed directly on encrypted data within the storage device, thus improving both processing capability and transfer speed
Solution Approach 2:
The encryption circuit acts as an intermediary component within the storage device that enables computational operations on encrypted data. This intermediary enables the storage device to handle large-scale data operations internally without requiring constant communication with the CPU for decryption/encryption operations, thereby improving both processing capability and data transfer efficiency
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An operating method for a storage device (30) including a storage controller (300) and a non-volatile memory (400) includes, receiving a command including data and a field related to the data from a host (40), determining an operation mode based on the command, selectively encrypting the data based on the operation mode to generate selectively encrypted data, and storing the selectively encrypted data in the non-volatile memory (400), wherein the selectively encrypting of the data includes encrypting the data based on a first encryption algorithm when the operation mode is a first operation mode, and encrypting the data based on a second encryption algorithm different from the first encryption algorithm when the operation mode is a second operation mode.