Bridge Controller Moniker-Based Encryption for Library Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data storage libraries face challenges in managing numerous decryption keys for mobile media located in various locations, making it difficult to ensure the security and integrity of encrypted data stored on mobile storage media.

Innovation Solution

A method and apparatus for storing encrypted data on a mobile storage medium that includes a combination bridge controller device capable of encrypting data packages, transmitting them along with a moniker associated with the decryption key and a message authentication code, and confirming successful decryption using the moniker and message authentication code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data encryption is implemented on mobile storage media, then data security is improved, but key management complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key management function from the encryption/decryption process by storing the moniker (key identifier) on the mobile media itself while keeping the actual decryption key in a secure key management system. This separation allows the media to be moved and accessed independently while the key remains securely managed centrally, reducing key management complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a moniker as an intermediary between the encrypted data and the decryption key. The moniker serves as a reference that links the encrypted data on mobile media to its corresponding decryption key in the key management system, simplifying key management by providing a straightforward lookup mechanism without requiring direct key storage on the media.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If decryption keys are changed frequently, then data security is improved, but management difficulty increases

Engineering Contradiction:
Improvedata securityVSAvoidmanagement ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent extracts the frequent key rotation capability from the mobile media to a centralized key management system. The media retains a stable moniker while the actual decryption keys can be rotated frequently in the key management system without requiring changes to the media or data structure, enabling frequent key changes while simplifying management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent performs preliminary action by establishing the moniker-key association in advance and storing it in the key management system. This pre-established linkage allows for efficient key rotation where new keys can be generated and associated with existing monikers without requiring media reformatting or data reencryption, facilitating frequent key changes with minimal operational overhead.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If message authentication code is stored with encrypted data, then data integrity verification is improved, but storage space requirement increases

Engineering Contradiction:
Improvedata integrity verificationVSAvoidstorage space
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent changes the parameter of the authentication code by using a compact fixed-length hash value (typically 128-256 bits) that provides sufficient integrity verification while occupying minimal storage space. This hash-based approach efficiently verifies data integrity without requiring extensive additional storage, as the authentication code is a fixed-size value regardless of the original data size.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8850231B2Data encryption using a key and moniker for mobile storage media adapted for library storage
Publication Date: 2014.09.30 SPECTRA LOGIC CORP
  • US8850231B2 patent drawing
  • US8850231B2 patent drawing
  • US8850231B2 patent drawing

AI summary

Disclosed are a method and apparatus for a data storage library comprising a plurality of drives and a combination bridge controller device adapted to direct and make compatible communication traffic between a client and the plurality of drives. The combination bridge controller device is further adapted to encrypt a first data package received from the client. The combination bridge controller device is further adapted to transmit the encrypted first data package, a first moniker and a first message authentication code to one of the plurality of drives for storage to a cooperating mobile storage medium. The combination bridge controller device is further adapted to decrypt the first data package when used in combination with a first key associated with the first moniker and guarantee the decryption of the first data package was successfully accomplished with authentication of the first message authentication code.