Bridge Controller Moniker-Based Encryption for Library Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Data storage libraries face challenges in managing numerous decryption keys for mobile media located in various locations, making it difficult to ensure the security and integrity of encrypted data stored on mobile storage media.
Innovation Solution
A method and apparatus for storing encrypted data on a mobile storage medium that includes a combination bridge controller device capable of encrypting data packages, transmitting them along with a moniker associated with the decryption key and a message authentication code, and confirming successful decryption using the moniker and message authentication code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data encryption is implemented on mobile storage media, then data security is improved, but key management complexity increases
Solution Approach 1:
The patent extracts the key management function from the encryption/decryption process by storing the moniker (key identifier) on the mobile media itself while keeping the actual decryption key in a secure key management system. This separation allows the media to be moved and accessed independently while the key remains securely managed centrally, reducing key management complexity while maintaining security.
Solution Approach 2:
The patent introduces a moniker as an intermediary between the encrypted data and the decryption key. The moniker serves as a reference that links the encrypted data on mobile media to its corresponding decryption key in the key management system, simplifying key management by providing a straightforward lookup mechanism without requiring direct key storage on the media.
2Reliability
If decryption keys are changed frequently, then data security is improved, but management difficulty increases
Solution Approach 1:
The patent extracts the frequent key rotation capability from the mobile media to a centralized key management system. The media retains a stable moniker while the actual decryption keys can be rotated frequently in the key management system without requiring changes to the media or data structure, enabling frequent key changes while simplifying management.
Solution Approach 2:
The patent performs preliminary action by establishing the moniker-key association in advance and storing it in the key management system. This pre-established linkage allows for efficient key rotation where new keys can be generated and associated with existing monikers without requiring media reformatting or data reencryption, facilitating frequent key changes with minimal operational overhead.
3Reliability
If message authentication code is stored with encrypted data, then data integrity verification is improved, but storage space requirement increases
Solution Approach 1:
The patent changes the parameter of the authentication code by using a compact fixed-length hash value (typically 128-256 bits) that provides sufficient integrity verification while occupying minimal storage space. This hash-based approach efficiently verifies data integrity without requiring extensive additional storage, as the authentication code is a fixed-size value regardless of the original data size.
Data Source
AI summary
Disclosed are a method and apparatus for a data storage library comprising a plurality of drives and a combination bridge controller device adapted to direct and make compatible communication traffic between a client and the plurality of drives. The combination bridge controller device is further adapted to encrypt a first data package received from the client. The combination bridge controller device is further adapted to transmit the encrypted first data package, a first moniker and a first message authentication code to one of the plurality of drives for storage to a cooperating mobile storage medium. The combination bridge controller device is further adapted to decrypt the first data package when used in combination with a first key associated with the first moniker and guarantee the decryption of the first data package was successfully accomplished with authentication of the first message authentication code.


