Drive Locking Key Migration Across KMS Without Data Loss

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Migrating between different key management servers (KMS) in information handling systems often results in data loss and disruption due to the need for data backups and migrations, especially when changing KMS vendors.

Innovation Solution

A method involving a baseboard management controller (BMC) and vendor fabric controller that enables seamless migration of security encryption keys between KMS systems by transitioning from local key management to external key management, allowing for continuous encryption key generation and management without data loss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data backups and migrations are performed when changing KMS vendors, then data can be preserved, but operational disruption and time loss occur

Engineering Contradiction:
Improvedata preservationVSAvoidoperational disruption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by establishing a second KMS connection and generating migration keys before actually migrating data. The BMC proactively configures the system to accept keys from a new KMS while maintaining the old connection, allowing seamless transition without data loss or operational disruption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The BMC acts as an intermediary between the storage device and KMS systems during migration. It manages multiple KMS connections simultaneously, orchestrating the key migration process and ensuring continuous data protection throughout the transition from the first KMS to the second KMS.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If local key management is used, then operational autonomy is improved, but security and management complexity worsen

Engineering Contradiction:
Improveoperational autonomyVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The BMC provides self-service capabilities by automatically managing encryption keys through external KMS. The system can autonomously request, receive, and manage encryption keys from external KMS services without manual intervention, combining operational simplicity with enhanced security management.

Inventive Principle:
Principle #25Self-service

3Reliability

If external key management services are used, then security is enhanced, but dependency on external services increases

Engineering Contradiction:
ImprovesecurityVSAvoiddependency on external services
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The BMC is designed with multi-functionality to work with multiple KMS vendors and services. It can manage encryption keys from different external KMS providers through a unified interface, reducing the impact of vendor-specific complexities and providing flexibility in external service dependencies.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12547741B2Dynamically migrating drive locking keys across key management servers
Publication Date: 2026.02.10 DELL PROD LP
  • US12547741B2 patent drawing
  • US12547741B2 patent drawing
  • US12547741B2 patent drawing

AI summary

An information handling system includes a BMC configurable in a first mode to provide external encryption keys for transactions with a storage device from external key management services, and in a second mode to generate local encryption keys for the transactions. At a first time, the BMC is configured in the first mode to provide external encryption keys for the transactions from a first external key management service. At a second time subsequent to the first time, the BMC is configured in the second mode to generate local encryption keys for the transactions. At a third time subsequent to the second time, the BMC is configured in the first mode to provide second external encryption keys for the transactions from a second external key management service. After the third time, no user data is lost on the first storage device as compared with a time prior to the first time.