Distributed Encryption Key Shares for HDD Cartridge Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The separation of printed circuit board assemblies (PCBAs) from hard disc drive (HDD) cartridges creates challenges in securely storing and managing encryption keys, particularly in shared storage systems where read/write control electronics are centralized, leading to data security vulnerabilities.
Innovation Solution
Implementing a secret sharing method that distributes encryption key shares among multiple devices, including HDD cartridges and PCBAs, such that a combination of shares meeting a threshold cardinality can reconstruct the key, ensuring secure data retrieval and access to security features.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If encryption keys are stored centrally in shared PCBAs, then data access is simplified, but data security vulnerabilities increase
Solution Approach 1:
The encryption key is segmented into multiple shares and distributed across different devices (HDD cartridges and PCBAs). Each device holds only a portion of the key, making it impossible to decrypt data without collecting sufficient shares from multiple devices. This segmentation resolves the contradiction by maintaining secure distributed storage while enabling coordinated access.
Solution Approach 2:
A key management system acts as an intermediary that coordinates key share distribution and verification. The system manages the threshold logic and facilitates secure key reconstruction when sufficient shares are collected, enabling simplified access procedures while maintaining security through the intermediary's control mechanisms.
2Reliability
If encryption keys are stored in each individual HDD cartridge, then data security is improved, but device complexity increases
Solution Approach 1:
Multiple HDD cartridges share a common key management infrastructure and use the same secret sharing scheme. Instead of each cartridge having completely independent key management, the system merges the key storage approach across devices while distributing shares, reducing individual device complexity while maintaining overall security.
3Ease of manufacture
If PCBA is separated from HDD cartridge, then cost is reduced, but key distribution and security management becomes more difficult
Solution Approach 1:
The key share distribution system is designed to be universal across different device types (HDD cartridges and PCBAs). The same secret sharing mechanism and key management protocols are used regardless of whether the share is stored in a cartridge or on a separate PCBA, simplifying the overall key distribution architecture despite physical separation.
Data Source
AI summary
In at least one implementation, technology disclosed herein provides a method including generating a plurality of shares of an encryption key such that a combination of shares having a cardinality above a threshold cardinality is sufficient to retrieve data encrypted with the encryption key, distributing the plurality of shares among a plurality of devices, the plurality of devices including one or more disc drive cartridges and one or more printed circuit board assemblies (PCBAs) configured to host one or more of the disc drive cartridges, receiving one or more of the plurality of shares from the plurality of devices, and in response to determining that cardinality of the received one or more of the plurality of shares is above the threshold cardinality, retrieving the data encrypted with the key.


