Flexible In-NAND Cryptographic Processing for Secure Flash Storage

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Noh, Seock-Hwan, Lee, Hoyeon, Kim, Junkyum, Im, Junsu, Park, Jay H., Lee, Sungjin, Noh, Sam H., Kim, Yeseong, Kung, Jaeha
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908664424562688
author Noh, Seock-Hwan
Lee, Hoyeon
Kim, Junkyum
Im, Junsu
Park, Jay H.
Lee, Sungjin
Noh, Sam H.
Kim, Yeseong
Kung, Jaeha
author_facet Noh, Seock-Hwan
Lee, Hoyeon
Kim, Junkyum
Im, Junsu
Park, Jay H.
Lee, Sungjin
Noh, Sam H.
Kim, Yeseong
Kung, Jaeha
contents We present FlashVault, an in-NAND self-encryption architecture that embeds a reconfigurable cryptographic engine into the unused silicon area of a state-of-the-art 4D V-NAND structure. FlashVault supports not only block ciphers for data encryption but also public-key and post-quantum algorithms for digital signatures, all within the NAND flash chip. This design enables each NAND chip to operate as a self-contained enclave without incurring area overhead, while eliminating the need for off-chip encryption. We implement FlashVault at the register-transfer level (RTL) and perform place-and-route (P&R) for accurate power/area evaluation. Our analysis shows that the power budget determines the number of cryptographic engines per NAND chip. We integrate this architectural choice into a full-system simulation and evaluate its performance on a wide range of cryptographic algorithms. Our results show that FlashVault consistently outperforms both CPU-based encryption (1.46~3.45x) and near-core processing architecture (1.02~2.01x), demonstrating its effectiveness as a secure SSD architecture that meets diverse cryptographic requirements imposed by regulatory standards and enterprise policies.
format Preprint
id arxiv_https___arxiv_org_abs_2508_03866
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Flexible In-NAND Cryptographic Processing for Secure Flash Storage
Noh, Seock-Hwan
Lee, Hoyeon
Kim, Junkyum
Im, Junsu
Park, Jay H.
Lee, Sungjin
Noh, Sam H.
Kim, Yeseong
Kung, Jaeha
Hardware Architecture
We present FlashVault, an in-NAND self-encryption architecture that embeds a reconfigurable cryptographic engine into the unused silicon area of a state-of-the-art 4D V-NAND structure. FlashVault supports not only block ciphers for data encryption but also public-key and post-quantum algorithms for digital signatures, all within the NAND flash chip. This design enables each NAND chip to operate as a self-contained enclave without incurring area overhead, while eliminating the need for off-chip encryption. We implement FlashVault at the register-transfer level (RTL) and perform place-and-route (P&R) for accurate power/area evaluation. Our analysis shows that the power budget determines the number of cryptographic engines per NAND chip. We integrate this architectural choice into a full-system simulation and evaluate its performance on a wide range of cryptographic algorithms. Our results show that FlashVault consistently outperforms both CPU-based encryption (1.46~3.45x) and near-core processing architecture (1.02~2.01x), demonstrating its effectiveness as a secure SSD architecture that meets diverse cryptographic requirements imposed by regulatory standards and enterprise policies.
title Flexible In-NAND Cryptographic Processing for Secure Flash Storage
topic Hardware Architecture
url https://arxiv.org/abs/2508.03866