Self-encrypting storage device and method for operating the same
The self-encrypting storage device uses a wireless communication module to securely transmit decryption commands, addressing security risks by ensuring data integrity and preventing unauthorized access, even if the device is compromised.
Patent Information
- Application Number
- JP2024153613
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-07-31
- Filing Date
- 2024-09-06
- Publication Date
- 2026-02-16
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing self-encrypting drives face security risks due to decryption commands or authentication information being sniffed by main computers, and data can be leaked or decrypted if the device is stolen and its casing is destroyed.
A self-encrypting storage device with a wireless communication module that converts wireless signals into cable signals to transmit decryption commands or authentication information to a control unit, disabling the self-encrypting function and allowing authorized operations on specific memory segments, with enhanced security features like distance-based warnings and multiple signal channels.
The solution prevents data leakage and theft by ensuring data remains secure even if the device is stolen or destroyed, providing flexible security settings and multiple protection layers.
Smart Images

Figure 2026025795000001_ABST
Abstract
Description
[Technical Field]
[0001] The present invention provides a self-encrypting storage device that obtains operational authority within the self-encrypting storage device through a decryption command from an external device. [Background technology]
[0002] The security of data storage is one of the key points of information security, and if valuable data is stolen, the loss will be huge. In particular, when it comes to portable data storage devices, there is a risk of important information being leaked due to reasons such as leaving it behind while traveling.
[0003] Although the built-in authentication system of a self-encrypting drive can maintain the security of internal data and enhance the security of data stored in the portable data storage device, there are still some concerns. In some operating methods, the decryption command or authentication information must still be decrypted by the main computer for the self-encrypting drive. As such, the decryption command or authentication information can still be sniffed by the main computer, resulting in the leakage of data stored in the portable data storage device, which poses security concerns.
[0004] In addition, as is well known, if a portable data storage device is stolen and the casing is destroyed, someone with knowledge can easily decrypt the encryption through the parts inside, causing data leakage, and if the device contains important confidential company documents, the loss could be unimaginable. Summary of the Invention [Means for solving the problem]
[0005] In response to the needs of the above technology, the present invention provides a self-encrypting storage device, which is used for storing data and provides a self-encrypting function for data, includes: a control unit connected to the data storage device through a first signal connection; and a wireless communication module connected to the control unit through a second signal connection, wherein the wireless communication module receives a wireless signal from a first external device, converts the wireless signal into a cable signal, and transmits it to the control unit, wherein the wireless signal carries a decryption command or authentication information corresponding to the data storage device, and the control unit transmits the decryption command or authentication information to the data storage device, and the data storage device disables the self-encrypting function according to the decryption command or authentication information to obtain the authority to operate at least one memory segment in the data storage device.
[0006] In one embodiment, when the wireless signal contains a decryption command or authentication information, the data storage device performs an authorized operation on at least one memory segment according to the operation authority. Alternatively, the self-encrypting storage device further includes a connector and a signal network bridge, and the control unit forms a signal channel with a second external device through the connector or the signal network bridge, wherein when the wireless signal contains a decryption command or authentication information, the second external device performs an authorized operation on at least one memory segment of the data storage device through the signal channel under the operation authority.
[0007] In one embodiment, the control unit determines the distance between the self-encrypting storage device and the first external device based on the strength of the wireless signal received by the wireless communication module. If the connector is not connected to the second external device and the distance between the decrypted self-encrypting device and the first external device exceeds the safe distance, the control unit issues a safety warning. Alternatively, if the control unit does not establish a signal channel with the second external device through the signal network bridge and the distance between the decrypted self-encrypting device and the first external device exceeds the safe distance, the control unit issues a safety warning.
[0008] In some embodiments, the second external device may include a computer, a peripheral storage device, a tablet computer, a smartphone, a display, or a printer, and may also include a device that transmits decryption instructions or authentication information for a corresponding data storage device in a wireless signal.
[0009] In one embodiment, the data storage device is a self-encrypting drive that complies with the TCG Opal 2.0 standard, a standard established by the Trusted Computing Group (TCG), an international industry group that develops standards to improve the reliability and security of computer equipment.
[0010] In one embodiment, the operation permissions include read permission, write permission, modify permission and execute permission.
[0011] In an embodiment, the data is digital data or simulation data.
[0012] In some embodiments, the second external device includes a computer, a peripheral storage device, a tablet computer, a smartphone, a display, or a printer.
[0013] In some embodiments, the first and second signal connections are each a cable connection or a wireless connection.
[0014] In some embodiments, the wireless signal includes NFC, Bluetooth, or other similar communication protocols.
[0015] In one embodiment, the self-encryption function encrypts and decrypts according to at least one of the Advanced Encryption Standard (AES) and the RSA encryption standard.
[0016] In another aspect, the present invention provides a method for operating a self-encrypting storage device, the method including the steps of: providing a data storage device, the data storage device providing a self-encrypting function for data stored in the data storage device; providing a first signal connection and a control unit, the control unit being connected to the data storage device through a first signal connection; providing a second signal connection and a wireless communication module, the wireless communication module being connected to the control unit through a second signal connection; the wireless communication module receiving a wireless signal from a first external device, converting the wireless signal into a cable signal, and transmitting the cable signal to the control unit, wherein the wireless signal sends a decryption command or authentication information corresponding to the data storage device, and the data storage device deactivating the self-encrypting function of the data storage device according to the decryption command or authentication information to obtain authorization to operate at least one memory segment in the data storage device. [Effects of the Invention]
[0017] In this way, the self-encrypting storage device and the operating method of the self-encrypting storage provided by the present invention can avoid the storage device of the present invention being stolen, and then the casing being destroyed and the encrypted data inside being stolen. [Brief explanation of the drawings]
[0018] [Figure 1] 1 is a simplified diagram illustrating a self-encrypting storage device according to multiple embodiments of the present invention. [Figure 2] 1 is a simplified diagram illustrating a self-encrypting storage device according to multiple embodiments of the present invention. [Figure 3] 1 is a diagram illustrating the distance between a self-encrypting storage device and a first external device, according to some embodiments of the present invention. [Figure 4] 1 is a flowchart illustrating encryption of a self-encrypting drive according to some embodiments of the present invention. [Figure 5] 1 is a flow chart providing a method of operating a self-encrypting storage in accordance with certain embodiments of the present invention. DETAILED DESCRIPTION OF THE INVENTION
[0019] The technical means, features and effects of the present invention will be described in more detail below with reference to the drawings and preferred embodiments.
[0020] As shown in FIG. 1, in response to the needs of the above technology, the present invention includes a data storage device 10 used for data storage and providing data self-encryption function, a control unit 20 connected to the data storage device 10 via a first signal connection SCN1, and a wireless communication module 30 connected to the control unit 20 via a second signal connection SCN2. The wireless communication module 30 receives a wireless signal WLS from a first external device ODE1, converts the wireless signal WLS into a cable signal, and transmits it to the control unit 20. When a decryption command or authentication information corresponding to the data storage device 10 is sent in the wireless signal WLS, the data storage device 10 disables the self-encryption function of the data storage device 10 according to the decryption command or authentication information (e.g., the control unit 20 transmits the decryption command or authentication information to the data storage device 10, or the control unit 20 sends a decryption command to the data storage device 10 according to the decryption command or authentication information, thereby obtaining the operation authority for at least one storage segment in the data storage device 10). Meanwhile, different users may have different security authorities corresponding to different data or segments in the data storage device 10. Therefore, since the decryption command or authentication information (or decryption command) may correspond to only a different memory segment therein, a self-encrypting storage device 100 is provided that unlocks the operation authority for only one memory segment in the data storage device 10 and performs the operation.
[0021] In addition, the design of the operation authority of at least one memory partition can greatly improve the usage efficiency of the data storage device 10, and different security settings can be set for different data or different memory partitions, so the self-encrypting storage device 100 has the flexibility to have various security settings.
[0022] In one embodiment, when the wireless signal WLS contains a decryption command or authentication information, the data storage device 10 performs an authorized operation on at least one memory segment according to the operating authority (for example, performs an authorized operation on the data storage device 10 itself, or performs an authorized operation on the data storage device 10 through the operation of the first external device ODE1).
[0023] 1, the self-encrypting storage device 200 shown in the embodiment of FIG. 2 further includes a connector CONN or a signal network bridge SBR, and the control unit 20 establishes a signal channel with the second external device ODE2 through the connector CONN or the signal network bridge SBR (e.g., the connector CONN is plugged into the second external device ODE2 to establish a signal channel between the self-encrypting storage device 100 and the second external device ODE2). When the wireless signal WLS contains a decryption command or authentication information, the second external device ODE2 performs an authorized operation on at least one memory segment of the data storage device 10 under its operating authority through the signal channel.
[0024] In one embodiment, if there is a need for enhanced security, a signal connection can be made between the first external device ODE1 and the self-encrypting storage device 100, 200, and in addition to the wireless signal WLS, other signals can be added to auxiliary transmit decryption commands or authentication information, such as images, videos, mechanical vibrations, sounds, images, biometric recognition, etc., to reduce the possibility of information theft and improve the strength of data confidentiality.
[0025] The self-encryption function will automatically encrypt (auto-lock) the data storage device 10 when the connection between the connector CONN or the signal network bridge SBR and the second external device ODE2 is cut off (for example, when the connector CONN is removed from the second external device ODE2). If the data storage device 10 is destroyed, the wireless communication module 30 will receive and decrypt the wireless signal WLS from the first external device ODE1, otherwise the data storage device 10 will become unreadable.
[0026] As shown in FIG. 3 , in one embodiment, based on the need for enhanced data security, the control unit 20 determines the distance D between the self-encrypting storage device 100 and the first external device ODE1 based on the strength of the wireless signal WLS received by the wireless communication module 30. It will be explained that if the strength of the received wireless signal WLS decreases, the distance D between the self-encrypting storage device 100 and the first external device ODE1 increases. Conversely, if the strength of the received wireless signal WLS increases, the distance D between the self-encrypting storage device 100 and the first external device ODE1 decreases. In this way, the distance D between the self-encrypting storage device 100 and the first external device ODE1 can be determined, and this technology can prevent theft of the self-encrypting storage device 100. For example, if the distance D between the self-encrypting storage device 100 (or 200) and the first external device ODE1 exceeds the safe distance, the control unit 20 issues a safety warning, prompting the self-encrypting storage device 100 to be removed from the site. Furthermore, for example, if the connector CONN is not inserted into the second external device ODE2 and the distance D between the decrypted self-encrypting storage device 100 and the first external device ODE1 exceeds the safety distance, the control unit 20 will issue a safety warning. Various types of safety warnings can be issued, including vibration, flashing, sound, and sending a signal to the first external device ODE1. Alternatively, the control unit 20 can establish a signal channel with the second external device ODE2 through a signal network bridge, and if the distance D between the decrypted self-encrypting storage device 100 and the first external device ODE1 exceeds the safety distance, the control unit 20 will issue a safety warning. This design prevents the risk of theft due to the loss of the self-encryption function (due to system trouble, settings tampering, etc.), provides double protection, and can be removed after use.
[0027] In one embodiment, the second external device ODE2 includes a computer, a peripheral storage device, a tablet computer, a smartphone, a display, or a printer, and mainly includes a device that sends decryption commands or authentication information corresponding to the data storage device 10 in the wireless signal WLS.
[0028] In one embodiment, data storage device 10 is a self-encrypting drive that meets the TCG Opal 2.0 standard.
[0029] In TCG Opal 2.0, the Media Encryption Key (MEK) is the main key for protecting static data in the data storage device 10. Static means that the data is not in a state where an operation is being performed. The MEK can be generated in various ways, such as using a random number generator.
[0030] As shown in Figure 4, the media encryption key MEK is a key point for protecting static data in the data storage device 10 and is itself encrypted. The media encryption key MEK is encrypted through a key encryption key (KEK), which is specific data based on user ciphers, commands, or calculations. This key encryption key KEK is derived using a key derivation function (KDF). The media encryption key MEK is stored in encrypted form within the self-encrypting storage device 100, and any unencrypted media encryption keys MEK are only stored while the self-encrypting storage device 100 is powered on. If the self-encrypting storage device 100 loses power, the unencrypted media encryption keys MEK are lost. Additionally, TCG Opal 2.0 does not store unencrypted user ciphers or commands, thereby reducing the possibility of security leaks in the self-encrypting storage device 100.
[0031] In one embodiment, the operation permissions include read, write, modify, and execute permissions. The operation permissions correspond to these operation permissions, and the operations performed on at least one partition of the data storage device 10 include read, write, modify, and execute. However, this is not limited to this, and multiple encryptions are also possible if necessary.
[0032] In some embodiments, the data is digital data or simulated data, and the data storage method includes electrical physics (voltage, resistance, capacitance, electromagnetic, quantum state), optical physics, chemical, mechanical, etc.
[0033] In some embodiments, the second external device ODE2 includes a computer, a peripheral storage device, a tablet computer, a smartphone, a display, or a printer.
[0034] In one embodiment, the data storage device 10 is a self-encrypting drive that meets the TCG Opal 2.0 standard. For example, it is a self-encrypting SSD hard disk (SATA hard disk or NVMe hard disk). NVMe hard disks are based on NAND and are transmitted to and from high-speed PCIe slots, transmitting data volumes dozens of times greater than SATA hard disks. NVMe hard disks can process over a million input / output operations per second (IOPS). Compared to NVMe hard disks, SATA hard disks have a more traditional architecture, and SATA hard disks are still used in many devices.
[0035] In one embodiment, the first and second signal connections SCN1 and SCN2 can be cable connections or wireless connections, respectively. The connection method can be determined as needed. For example, in the cable connection method, the internal design of the self-encrypting storage device is relatively crowded, but the connection content is difficult to eavesdrop on. In the wireless connection method, the internal design of the self-encrypting storage device is flexible, but the connection content is easy to eavesdrop on. In addition, if the first and second signal connections SCN1 and SCN2 are cable connections, the communication protocol can be determined as needed. For example, cable transmission methods such as I2C and SPI can be used.
[0036] In one embodiment, the wireless signal WLS may use NFC, Bluetooth, or other similar communication protocols.
[0037] In one embodiment, the self-encryption function encrypts and decrypts according to at least one of the Advanced Encryption Standard (AES) and the RSA encryption standard.
[0038] In an embodiment, if necessary, the first external device ODE1 and the second external device ODE2 can be the same device, for example, the same device can communicate with the wireless communication module 30 via the wireless signal WLS through the NFC, Bluetooth, or other similar communication protocols. At this time, a signal network bridge SBR can be integrated with the wireless communication module 30, and the same device can be signal-connected to the data storage device 10 through the wireless signal WLS for operation.
[0039] As shown in FIG. 5, from another perspective, the present invention provides a method for operating a self-encrypting storage, the method including: providing a data storage device 10 (S1), the data storage device 10 providing a self-encrypting function for data stored in the data storage device 10; providing a first signal connection SCN1 and a control unit 20 (S2), the control unit 20 being connected to the data storage device through a first signal connection SCN1; providing a second signal connection SCN2 and a wireless communication module 30 (S3), the wireless communication module 30 being connected to the control unit 20 through a second signal connection SCN2; the wireless communication module 30 receiving a wireless signal WLS from a first external device ODE1, converting the wireless signal WLS into a cable signal, and transmitting the cable signal to the control unit 20 (S4); and when a decryption command or authentication information corresponding to the data storage device 10 is sent in the wireless signal WLS (S5), the data storage device 10 deactivates the self-encrypting function of the data storage device 10 according to the decryption command or authentication information, and obtains the operation authority for at least one memory segment in the data storage device 10 (S6).
[0040] For a detailed explanation of the operation method of the self-encrypting storage device, please refer to the related embodiments and component descriptions above, and will not be detailed here. The main technical means of the present invention is that the data storage device 10 has a self-encrypting function (S1), so that even if an unauthorized person destroys the product casing and removes the components individually, the data in the data storage device 10 cannot be read, whether through the control unit 20, the wireless communication module 30, or the data storage device 10 alone.
[0041] The above content has been described by taking the best embodiment as an example of the present invention, and its purpose is to make it easier for those skilled in the art to understand the content of the present invention, and is not intended to limit the scope of the claims and the disclosed technology of the present invention. Those skilled in the art can derive equivalent embodiments by combining the above content with slight variations and modifications without departing from the spirit of the technical means of this application. [Explanation of symbols]
[0042] 100, 200: Self-encrypting storage 10: Data storage device 20: Control unit 30: Wireless communication module CONN: Connector D: Distance KEK: Key Encryption Key MEK: Media Encryption Key ODE1: First external device ODE2: Second external device S1-S6: Stages SBR: Signaling Network Bridge SCN1: First signal connection SCN2: Second signal connection WLS: Wireless signal
Claims
1. a data storage device used to store data and providing self-encryption functionality to the data; a control unit connected to the data storage device via a first signal connection; and a wireless communication module connected to the control unit through a second signal connection; the wireless communication module receives a wireless signal from the first external device, converts the wireless signal into a cable signal, and transmits it to the control unit; when the wireless signal carries a decryption command or authentication information corresponding to the data storage device, the control unit transmits the decryption command or authentication information to the data storage device, and the data storage device deactivates its self-encryption function according to the decryption command or authentication information, and obtains the operation authority for at least one memory segment in the data storage device; Self-encrypting storage.
2. 2. The self-encrypting storage device of claim 1, wherein when the wireless signal contains a decryption command or authentication information, the data storage device performs an authorized operation on at least one memory segment according to the operating authority; or the self-encrypting storage device further includes a connector and a signal network bridge, which is used for inserting a second external device, and the control unit forms a signal channel with the second external device through the connector or the signal network bridge, wherein when the wireless signal contains a decryption command or authentication information, the second external device performs an authorized operation on at least one memory segment of the data storage device through the signal channel under the operating authority.
3. 2. The self-encrypting storage device of claim 1, wherein the control unit determines the distance between the self-encrypting storage device and the first external device based on the strength of the wireless signal received by the wireless communication module, and if the distance between the decrypted self-encrypting device and the first external device exceeds a safety distance, the control unit issues a safety warning.
4. The self-encrypting storage device of claim 2 , wherein the second external device comprises a computer, a peripheral storage device, a tablet computer, a smartphone, a display, or a printer.
5. 2. The self-encrypting storage device of claim 1, wherein the data storage device is a self-encrypting drive that meets the TCG Opal 2.0 standard.
6. The self-encrypting storage device of claim 1 , wherein the operation permissions include a read permission, a write permission, a modify permission, and an execute permission.
7. The self-encrypting storage device according to claim 1 , wherein the data is digital data or simulation data.
8. 2. The self-encrypting storage device of claim 1, wherein the first and second signal connections are each a cable connection or a wireless connection.
9. The self-encrypting storage device of claim 1 , wherein the wireless signal comprises NFC, Bluetooth, or other communication protocols.
10. 2. The self-encrypting storage device according to claim 1, wherein the self-encrypting function encrypts and decrypts data according to at least one of the Advanced Encryption Standard (AES) and the RSA encryption standard.
11. providing a data storage device that provides self-encryption capabilities for data stored within the data storage device; providing a first signal connection and a control unit, the control unit being connected to a data storage device through the first signal connection; providing a second signal connection and a wireless communication module, the wireless communication module being connected to the control unit through the second signal connection; and the wireless communication module receives a wireless signal from the first external device, converts the wireless signal into a cable signal, and transmits it to the control unit, wherein when the wireless signal sends a decryption command or authentication information corresponding to the data storage device, the data storage device unlocks its self-encryption function according to the decryption command or authentication information to obtain the operation authority for at least one memory segment in the data storage device; How to operate self-encrypting storage.
Citation Information
Patent Citations
Memory card lock device
JP2022023765A
Flash drive to be locked by wireless communication
JP2023021894A
Secure control of self-encrypting storage devices
US20170277916A1
Door Lock Control with Wireless User Authentication
US20200366470A1
Data transfer method and memory storage device
US20210294523A1