Dual-Interface Storage Drive Authentication Before PCIe Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to verify the authenticity of storage devices connected via PCIe before establishing a link, posing risks of unauthorized access and memory destruction.
Innovation Solution
Implementing a dual-channel communication system with a first interface that cannot access the host memory and a second interface that can, allowing authenticity verification before establishing the second interface connection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If PCIe interface is used for high-speed communication between storage device and host, then communication speed is improved, but security risk increases due to direct memory access capability
Solution Approach 1:
The communication interface is segmented into two distinct channels: a first communication channel (e.g., I2C bus) for authentication purposes only, and a second communication channel (PCIe) for high-speed data transfer. This segmentation allows the system to separate security verification functions from data transmission functions, enabling fast communication while preventing unauthorized access through controlled channel usage.
Solution Approach 2:
Authentication verification is performed in advance through the first communication channel before enabling the second PCIe communication channel. This preliminary action ensures that the storage device's authenticity is confirmed prior to granting memory access capabilities, preventing unauthorized devices from exploiting the fast PCIe interface for malicious purposes.
2Reliability
If authentication verification is performed before link establishment, then security is improved, but system complexity increases due to dual-channel requirement
Solution Approach 1:
The storage device is designed with multi-functionality, incorporating both a first communication interface (e.g., I2C) for authentication and a second interface (PCIe) for data transfer within a single device unit. This multi-functionality allows the storage device to perform both security verification and high-speed communication roles, reducing the need for separate dedicated authentication hardware and thereby limiting overall system complexity.
3Speed
If unauthorized device is connected to PCIe, then memory access speed is improved, but memory security deteriorates due to potential destruction
Solution Approach 1:
The first communication channel (e.g., I2C bus) acts as an intermediary between the host and the storage device for authentication purposes. This intermediary channel enables security verification without requiring the high-speed PCIe channel to be active during authentication, thereby preventing unauthorized devices from directly accessing memory through the fast PCIe interface while still allowing legitimate devices to achieve high-speed access after verification.
Data Source
AI summary
The present invention relates to a storage system capable of connecting a drive having multiple kinds of interfaces and comprising a storage controller having a processor and built-in memory. When the drive and storage controller are connected, a plurality of communication channels are formed between them. The plurality of communication channels include a first communication channel, via a first interface, incapable of accessing the built-in memory even when the communication connection is established, and a second communication channel, via a second interface, capable of accessing the built-in memory when the communication connection is established. At a specified timing when the communication connection via the second communication channel is not established, the processor executes authenticity verification processing of the drive based on information acquired from the drive by using the first communication channel; and permits establishment of the communication connection via the second communication channel when the authenticity is confirmed.


