Dual-Key HDD Encryption Without Data Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

End users face difficulties in generating their own encryption keys for encrypted hard disk drives (HDDs) without causing a cryptographic erase of existing data, which requires costly and time-consuming reinstallation of the operating system and software, especially for businesses receiving multiple systems with default manufacturer-generated keys.

Innovation Solution

Implementing a dual-key encryption system where a default encryption key is used initially, and an end-user-generated secondary key can be created without erasing existing data, allowing seamless transition to the new key for future data encryption while maintaining access to pre-existing data encrypted with the default key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a default encryption key is used for encrypting data on the HDD, then data security is maintained and data can be automatically encrypted, but end users cannot generate their own encryption keys without causing cryptographic erase of existing data

Engineering Contradiction:
Improveuser ability to generate own encryption keyVSAvoiddata accessibility
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the encryption key management into multiple independent keys (default key and user-generated key) that can coexist. Each key encrypts specific portions of data, allowing the system to maintain both the manufacturer's default encryption and user-controlled encryption simultaneously without requiring cryptographic erase of existing data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to key management by implementing a dual-key architecture where data can be encrypted with either the default key or the user-generated key. This dimensional expansion allows the system to support multiple encryption scenarios without compromising existing data accessibility.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Ease of operation

If an end user generates a new encryption key, then data security control is improved, but reinstallation of operating system and software is required which is costly and time-consuming

Engineering Contradiction:
Improveuser control over encryption keyVSAvoidreinstallation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent performs preliminary action by pre-configuring the HDD to support multiple encryption keys and pre-encrypting existing data with the default key. This preliminary setup allows users to later generate their own keys without requiring reinstallation, as the system is already prepared to handle multiple key scenarios.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism (the dual-key encryption system) that mediates between the default encryption and user-generated encryption. This intermediary layer allows seamless transition and coexistence of different encryption keys without requiring system reinstallation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a single encryption key is used for the HDD, then the encryption system is simple, but users must trust the default key generated by the supplier which compromises security autonomy

Engineering Contradiction:
Improveencryption key systemVSAvoiduser trust in encryption
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the single encryption key system into multiple independent keys (default key and user-generated key). This segmentation allows users to have their own key while the system maintains support for the default key, reducing complexity rather than increasing it while improving user trust and security autonomy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8886962B2Systems and methods for disk encryption with two keys
Publication Date: 2014.11.11 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8886962B2 patent drawing
  • US8886962B2 patent drawing
  • US8886962B2 patent drawing

AI summary

Embodiments provide for using two encryption keys to encrypt data instead of only one as is customarily used in the industry. According to various embodiments, a default encryption key is generated and is initially used to encrypt data, while a second encryption key is available for generation by an end user. Embodiments provide that data is encrypted with the default key until the user generates their own key, after this event, all data is encrypted with key generated by the user.