Unified Encryption Key for Cache and Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In existing storage systems, the encryption keys used for data stored in a cache and those used in the final storage destination are different, leading to inconsistent security levels.

Innovation Solution

A storage system is designed where the encryption key used for data stored in the cache is identical to the encryption key used in the final storage destination, ensuring that both the cache and the storage apparatus maintain the same security level by using a unified encryption key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If different encryption keys are used for cache and storage apparatus, then data can be stored in non-volatile memory with basic protection, but security levels become inconsistent between cache and final storage

Engineering Contradiction:
Improvesecurity level consistencyVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the encryption key management for cache and storage apparatus by making the cache encryption key identical to the storage apparatus encryption key. This is achieved by the cache control apparatus acquiring the storage apparatus encryption key and using it for encrypting cache data, thereby unifying the encryption mechanism across both components and ensuring consistent security levels.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The storage apparatus encryption key serves a dual function: it encrypts data in the storage apparatus and also encrypts data in the cache. This universal key approach eliminates the need for separate key management systems, reducing complexity while maintaining consistent security across different storage layers.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If encryption keys are unified between cache and storage apparatus, then security levels become consistent, but key management becomes more complex

Engineering Contradiction:
Improvedata protection consistencyVSAvoidsecurity management simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The cache control apparatus acts as an intermediary that acquires the storage apparatus encryption key and manages its usage for cache encryption. This intermediary role simplifies key management by centralizing the key acquisition and distribution process, making security management easier while ensuring consistent encryption across cache and storage apparatus.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate encryption keys are used for cache and storage, then key management can be independent, but data security levels differ between cache and final storage

Engineering Contradiction:
Improveencryption security uniformityVSAvoidencryption system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies homogeneity by using the same encryption key for both cache and storage apparatus, creating a uniform encryption system. This homogeneous approach ensures that data security levels are consistent across different storage layers, while the encryption system itself remains relatively simple by avoiding the need for multiple different key management mechanisms.

Inventive Principle:
Principle #33Homogeneity

Data Source

PatentUS10296468B2Storage system and cache control apparatus for storage system
Publication Date: 2019.05.21 HITACHI VANTARA LTD
  • US10296468B2 patent drawing
  • US10296468B2 patent drawing
  • US10296468B2 patent drawing

AI summary

An encryption key used with a storing apparatus and an encryption key used with a non-volatile cache memory are identical to each other. A cache control portion unit effects control in such a way that an encryption key EK used to encrypt first data stored in the storing apparatuses, and an encryption key EK used to encrypt second data which are data corresponding to the first data and are stored in the non-volatile cache memory, are identical to each other. If the cache control portion receives a write request and first data WD, the cache control portion identifies from the storing apparatuses a storing apparatus that is to be the storage destination of the first data, identifies an encryption key allocated to the identified storing apparatus, encrypts the second data corresponding to the first data using the identified encryption key, and stores the data in the non-volatile cache memory.