Self-Encrypting Storage Controller Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The introduction of dedicated hardware security modules (HSMs) for managing encryption keys in information processing systems is costly and limited in key management capacity, with a need for additional access control mechanisms.
Innovation Solution
A self-encrypting storage system, such as a solid-state drive (SSD), with a controller that generates, manages, and securely stores encryption keys using its built-in encryption and decryption functions, allowing for multiple key management and access control through extended commands and authentication processes, effectively replacing the need for dedicated HSMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If dedicated hardware security modules (HSMs) are introduced to securely manage encryption keys, then security is improved, but costs significantly increase
Solution Approach 1:
The patent combines the key management functions traditionally performed by dedicated HSM hardware into the storage device itself. The storage device integrates encryption/decryption processing units and key storage capabilities, merging security functions with storage functionality. This eliminates the need for separate HSM hardware, reducing costs while maintaining security through the integrated encryption/decryption capabilities and secure key management within the storage device.
Solution Approach 2:
The storage device is designed to perform multiple functions: data storage, data encryption, data decryption, and key management. The encryption/decryption processing unit can handle both user data and encryption keys, while the storage medium stores both data and keys. This multi-functional approach replaces dedicated HSM hardware, reducing costs while maintaining security through the device's ability to perform security-critical operations internally.
2Reliability
If dedicated hardware security modules (HSMs) are introduced to manage encryption keys, then security is improved, but the number of manageable encryption keys is limited
Solution Approach 1:
The storage device divides key management into organized groups and categories. Encryption keys are stored in the storage medium and managed through the controller, which can handle multiple keys simultaneously. The system segments keys into different categories (e.g., file system encryption keys, application-specific keys) and manages them through structured commands, enabling scalability to handle a large number of keys beyond the limitations of dedicated HSM hardware.
Solution Approach 2:
The key management system is designed to be dynamic and scalable. The controller can generate, store, manage, and delete encryption keys as needed through extended commands. The storage medium can accommodate a variable number of keys based on requirements, and the system can dynamically allocate key resources. This dynamic architecture allows the system to adapt to varying key management needs and scale to handle numerous keys without the fixed limitations of dedicated HSM hardware.
3Reliability
If dedicated hardware security modules (HSMs) are introduced to manage encryption keys, then security is improved, but a mechanism to manage access rights is required
Solution Approach 1:
The storage device performs self-service key management through its integrated controller and encryption/decryption processing units. The device autonomously generates, stores, manages, and protects encryption keys using its built-in security mechanisms. Access control is handled through authentication processes and authorized commands issued by hosts, eliminating the need for external dedicated HSM hardware and complex external access control mechanisms. The device manages its own security internally through structured command protocols and authentication verification.
4Ease of manufacture
If self-encrypting storage is used to manage encryption keys, then costs are reduced and key management capacity is increased, but access control mechanisms must be implemented
Solution Approach 1:
The controller acts as an intermediary between hosts and the encryption keys stored in the storage medium. It receives extended commands from hosts, verifies authentication, and manages key operations accordingly. The controller mediates access control by interpreting host commands, verifying credentials, and executing appropriate key management operations. This intermediary approach provides structured access control within the integrated architecture, managing security without requiring external dedicated HSM hardware or overly complex external control mechanisms.
Data Source
AI summary
According to one embodiment, a memory system includes a nonvolatile memory and a controller. The controller is communicable with a host and is configured to control the nonvolatile memory. The controller is configured to when receiving a key generation command from the host, generate an encryption key by an encrypting and decrypting function unit, store the encryption key in the nonvolatile memory, and transmit an identifier of the encryption key to the host.


