Storage Device Dual Memory Encryption Key Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Storage devices with self-encryption functions may fail to prevent data leakage when the storage device wears out, as the encryption key generation information is not properly erased due to device degradation, allowing encrypted data to be decrypted.

Innovation Solution

A storage device configuration that includes both a first nonvolatile memory for storing first encryption key generation information and a second nonvolatile memory with irreversible storage elements, where the controller generates an encryption key using both types of information and attempts to erase the first key generation information upon request, and if that fails, erases the second key generation information, ensuring data security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If encryption key generation information is stored in a single nonvolatile memory, then the storage device structure is simple, but the encryption key cannot be securely erased when the device wears out

Engineering Contradiction:
Improvememory structureVSAvoiddata security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The encryption key generation information is segmented into two separate nonvolatile memories: a first nonvolatile memory that can be erased and rewritten, and a second nonvolatile memory with irreversible storage elements. This segmentation allows the system to attempt erasure in the first memory while maintaining security through the second memory, resolving the contradiction between simple structure and secure erasure capability.

Inventive Principle:
Principle #1Segmentation

2Reliability

If encryption key generation information is stored in irreversible memory elements, then data security is maintained when device wears out, but the key cannot be regenerated or updated

Engineering Contradiction:
Improvedata securityVSAvoidkey update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements dynamic key management by attempting to store encryption key generation information in the erasable first nonvolatile memory during normal operation, allowing for key updates and regeneration. The irreversible second nonvolatile memory serves as a fallback security mechanism that activates only when the first memory cannot be erased, thus providing both adaptability and security.

Inventive Principle:
Principle #15Dynamics

3Ease of manufacture

If the storage device uses wear-prone memory for key storage, then the device can be manufactured with standard components, but the encryption key may not be erased due to wearing out

Engineering Contradiction:
Improvecomponent availabilityVSAvoiderasure reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system prepares for potential future erasure failures by pre-configuring a dual-memory architecture. The first nonvolatile memory (prone to wear) is used for normal key storage with full erasure capability, while the second nonvolatile memory with irreversible elements serves as a pre-prepared cushion or backup security mechanism that activates if the first memory fails to erase due to wear, thus ensuring erasure reliability without compromising manufacturability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11588634B2Storage device and controlling method
Publication Date: 2023.02.21 KIOXIA CORP
  • US11588634B2 patent drawing
  • US11588634B2 patent drawing
  • US11588634B2 patent drawing

AI summary

A storage device includes a first memory to which data can be written a plurality of times and a second memory that includes storage elements for which electrical characteristics can be changed only once. The first memory storing first encryption key information and the second memory storing second encryption key information. A controller generated an encryption key using the first encryption key information and the second encryption key information in combination and then encrypts and decrypts data written or read from the first memory. When a host requests an encryption erase, the controller attempts to erase the first encryption key information from the first memory. If the requested erase fails, the controller erases the second encryption key information from the second nonvolatile memory.