Storage Device Dual Memory Encryption Key Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Storage devices with self-encryption functions may fail to prevent data leakage when the storage device wears out, as the encryption key generation information is not properly erased due to device degradation, allowing encrypted data to be decrypted.
Innovation Solution
A storage device configuration that includes both a first nonvolatile memory for storing first encryption key generation information and a second nonvolatile memory with irreversible storage elements, where the controller generates an encryption key using both types of information and attempts to erase the first key generation information upon request, and if that fails, erases the second key generation information, ensuring data security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If encryption key generation information is stored in a single nonvolatile memory, then the storage device structure is simple, but the encryption key cannot be securely erased when the device wears out
Solution Approach 1:
The encryption key generation information is segmented into two separate nonvolatile memories: a first nonvolatile memory that can be erased and rewritten, and a second nonvolatile memory with irreversible storage elements. This segmentation allows the system to attempt erasure in the first memory while maintaining security through the second memory, resolving the contradiction between simple structure and secure erasure capability.
2Reliability
If encryption key generation information is stored in irreversible memory elements, then data security is maintained when device wears out, but the key cannot be regenerated or updated
Solution Approach 1:
The system implements dynamic key management by attempting to store encryption key generation information in the erasable first nonvolatile memory during normal operation, allowing for key updates and regeneration. The irreversible second nonvolatile memory serves as a fallback security mechanism that activates only when the first memory cannot be erased, thus providing both adaptability and security.
3Ease of manufacture
If the storage device uses wear-prone memory for key storage, then the device can be manufactured with standard components, but the encryption key may not be erased due to wearing out
Solution Approach 1:
The system prepares for potential future erasure failures by pre-configuring a dual-memory architecture. The first nonvolatile memory (prone to wear) is used for normal key storage with full erasure capability, while the second nonvolatile memory with irreversible elements serves as a pre-prepared cushion or backup security mechanism that activates if the first memory fails to erase due to wear, thus ensuring erasure reliability without compromising manufacturability.
Data Source
AI summary
A storage device includes a first memory to which data can be written a plurality of times and a second memory that includes storage elements for which electrical characteristics can be changed only once. The first memory storing first encryption key information and the second memory storing second encryption key information. A controller generated an encryption key using the first encryption key information and the second encryption key information in combination and then encrypts and decrypts data written or read from the first memory. When a host requests an encryption erase, the controller attempts to erase the first encryption key information from the first memory. If the requested erase fails, the controller erases the second encryption key information from the second nonvolatile memory.


