Automated Key Generation for Self-Encrypting Drives

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods for managing encryption keys in self-encrypting drives (SEDs) are time-consuming and difficult to scale, especially in large data centers, posing risks of data breaches and inefficiencies in clustered computing environments.

Innovation Solution

An automated key generation and management system using a service controller, such as a baseboard management controller (BMC), communicates with a key management server to generate, store, and distribute encryption keys, enabling efficient encryption and decryption of data across multiple SEDs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual key management methods are used for self-encrypting drives, then key generation can be performed, but the process becomes time-consuming and difficult to scale in large data centers

Engineering Contradiction:
Improvekey generation efficiencyVSAvoidkey management time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables self-service automation where the service controller automatically generates key requests, the key management server automatically generates and distributes encryption keys, and the storage controller automatically receives and implements keys without manual intervention. This automated workflow resolves the contradiction by eliminating time-consuming manual operations while maintaining scalable key generation capacity across large data centers

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The service controller proactively generates key requests and transmits them to the key management server before encryption operations are needed. The key management server prepares and stores keys in advance, ready for distribution to storage controllers. This preliminary automation of key management processes resolves the contradiction by eliminating reactive manual intervention while maintaining efficient key availability for large-scale deployments

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If automated key generation is implemented, then management efficiency improves, but system complexity increases due to additional components like service controller and key management server

Engineering Contradiction:
Improvekey management efficiencyVSAvoidsystem architecture complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system segments key management functions into distinct modular components: the service controller handles key request generation, the key management server handles key generation and distribution, and the storage controller handles key implementation. This segmentation resolves the contradiction by distributing complexity across specialized modules, making the overall system easier to operate despite the increased number of components

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The service controller and key management server are designed as universal components that can serve multiple storage controllers and self-encrypting drives simultaneously. The key management server provides centralized key generation and distribution services to numerous storage controllers, while the service controller manages key requests for multiple drives. This multi-functionality resolves the contradiction by justifying the added complexity through enhanced operational efficiency and scalability across large data centers

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encryption keys are managed manually, then system simplicity is maintained, but security risks increase due to potential data breaches and human error

Engineering Contradiction:
Improvedata securityVSAvoidkey management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The key management server acts as a secure intermediary between the service controller and storage controllers, centrally managing encryption key generation, storage, and distribution. This intermediary architecture resolves the contradiction by eliminating security risks associated with manual key management while containing complexity within the specialized key management component rather than distributing it across the entire system

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system extracts key management functions from the storage controllers and consolidates them in a dedicated key management server. This extraction resolves the contradiction by removing security vulnerabilities from individual storage controllers and centralizing security management in a specialized component, thereby improving overall data security while managing complexity through functional separation

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10069625B2System and method for automatic key generation for self-encrypting drives
Publication Date: 2018.09.04 QUANTA COMPUTER INC
  • US10069625B2 patent drawing
  • US10069625B2 patent drawing
  • US10069625B2 patent drawing

AI summary

Embodiments generally relate to data security in a computing system. The present technology discloses techniques that can enable an automatic generation of encryption keys using a service controller in communication with a key management server. By enabling an automatic mechanism for encryption key generation, the present technology can achieve data encryption efficiency for a large number of servers.