Dual-Key HDD Encryption Without Data Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
End users face difficulties in generating their own encryption keys for encrypted hard disk drives (HDDs) without causing a cryptographic erase of existing data, which requires costly and time-consuming reinstallation of the operating system and software, especially for businesses receiving multiple systems with default manufacturer-generated keys.
Innovation Solution
Implementing a dual-key encryption system where a default encryption key is used initially, and an end-user-generated secondary key can be created without erasing existing data, allowing seamless transition to the new key for future data encryption while maintaining access to pre-existing data encrypted with the default key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a default encryption key is used for encrypting data on the HDD, then data security is maintained and data can be automatically encrypted, but end users cannot generate their own encryption keys without causing cryptographic erase of existing data
Solution Approach 1:
The patent segments the encryption key management into multiple independent keys (default key and user-generated key) that can coexist. Each key encrypts specific portions of data, allowing the system to maintain both the manufacturer's default encryption and user-controlled encryption simultaneously without requiring cryptographic erase of existing data.
Solution Approach 2:
The patent introduces a new dimension to key management by implementing a dual-key architecture where data can be encrypted with either the default key or the user-generated key. This dimensional expansion allows the system to support multiple encryption scenarios without compromising existing data accessibility.
2Ease of operation
If an end user generates a new encryption key, then data security control is improved, but reinstallation of operating system and software is required which is costly and time-consuming
Solution Approach 1:
The patent performs preliminary action by pre-configuring the HDD to support multiple encryption keys and pre-encrypting existing data with the default key. This preliminary setup allows users to later generate their own keys without requiring reinstallation, as the system is already prepared to handle multiple key scenarios.
Solution Approach 2:
The patent introduces an intermediary mechanism (the dual-key encryption system) that mediates between the default encryption and user-generated encryption. This intermediary layer allows seamless transition and coexistence of different encryption keys without requiring system reinstallation.
3Device complexity
If a single encryption key is used for the HDD, then the encryption system is simple, but users must trust the default key generated by the supplier which compromises security autonomy
Solution Approach 1:
The patent segments the single encryption key system into multiple independent keys (default key and user-generated key). This segmentation allows users to have their own key while the system maintains support for the default key, reducing complexity rather than increasing it while improving user trust and security autonomy.
Data Source
AI summary
Embodiments provide for using two encryption keys to encrypt data instead of only one as is customarily used in the industry. According to various embodiments, a default encryption key is generated and is initially used to encrypt data, while a second encryption key is available for generation by an end user. Embodiments provide that data is encrypted with the default key until the user generates their own key, after this event, all data is encrypted with key generated by the user.


