Boot Time Reduction via Key Encryption Key Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing approaches for key encryption management in self-encrypting storage resources lead to increased boot times due to the need for a unique key encryption key per storage resource, as existing methods do not allow for identification of boot drives before they are accessed, resulting in delayed system boot in various storage topologies.

Innovation Solution

A management controller prioritizes the retrieval and decryption of key encryption keys for bootable storage resources over non-bootable ones during the boot process, allowing bootable storage resources to be unlocked first, thereby minimizing boot time.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a unique key encryption key per storage resource is used, then security is improved, but boot time increases

Engineering Contradiction:
ImprovesecurityVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the key management process by creating separate key management instances for bootable storage resources versus non-bootable storage resources. The management controller identifies bootable resources and retrieves their KEKs separately from non-bootable resources, allowing parallel processing and reducing overall boot time while maintaining unique KEKs for each storage resource.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary action by having the management controller identify bootable storage resources before the key retrieval process begins. This identification is performed during system initialization or boot sequence, allowing the controller to prioritize and pre-prepare key retrieval operations for critical bootable drives, thus reducing boot time without compromising security.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all storage resources are unlocked during boot, then security is maintained, but boot process is delayed

Engineering Contradiction:
ImprovesecurityVSAvoidboot speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies local quality by implementing different key retrieval priorities for different storage resources based on their function. Bootable storage resources receive high priority with immediate KEK retrieval, while non-bootable resources receive lower priority. This localized differentiation allows the system to optimize boot performance for critical resources without compromising security for non-critical resources.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements skipping by allowing the boot process to proceed without waiting for non-bootable storage resources to be unlocked. The management controller retrieves KEKs for bootable resources first and allows the boot sequence to continue, while KEK retrieval for non-bootable resources occurs in the background or after boot completion. This rushing through of critical operations eliminates unnecessary delays in the boot process.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11153075B2Systems and methods for minimizing boot time when using a unique key encryption key per storage resource in secure enterprise key management provisioning
Publication Date: 2021.10.19 DELL PROD LP
  • US11153075B2 patent drawing
  • US11153075B2 patent drawing
  • US11153075B2 patent drawing

AI summary

In accordance with embodiments of the present disclosure, a key management utility may be configured to, during boot of an information handling system, prioritize retrieval of key encryption keys of bootable storage resources of a plurality of storage resources over retrieval of key encryption keys of non-bootable storage resources of the plurality of storage resources and prioritize decryption of media encryption keys of bootable storage resources of the plurality of storage resources using their corresponding key encryption keys over decryption of media encryption keys of non-bootable storage resources of the plurality of storage resources using their corresponding key encryption keys.