Encryption Key Data Retention Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data retention policies are difficult to enforce at both the storage drive and system levels, leading to expired data remaining on storage devices, which poses security and legal risks and wastes storage capacity, as existing systems fail to ensure data is properly destroyed when it expires.

Innovation Solution

The use of encryption keys with associated retention policies, where data is encrypted and retained based on the validity of the encryption key, automatically marking and expiring data when the key expires, ensuring data is discarded during the recycling process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is retained on storage drive without automatic expiration enforcement, then storage capacity is utilized, but security risks and legal compliance issues arise from expired data remaining on devices

Engineering Contradiction:
Improvedata retention policy enforcementVSAvoidsecurity risks from expired data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by encrypting data with time-limited keys before storage and pre-scheduling key expiration. The controller automatically expires encryption keys after predetermined time periods, ensuring expired data is automatically rendered inaccessible without requiring manual intervention or external verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention extracts the access control mechanism from traditional permission-based systems and replaces it with encryption-based access control. By separating the encryption key from the data and controlling key availability through automatic expiration, the system removes the ability to access expired data while the data itself remains on the storage medium.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If manual data deletion processes are used to enforce retention policies, then data can be removed when needed, but the complexity of tracking and deleting expired data across the system increases

Engineering Contradiction:
Improvedata expiration enforcementVSAvoidsystem complexity for tracking expired data
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service by automatically managing the entire data expiration lifecycle. The controller monitors encryption key validity periods, automatically expires keys when time limits are reached, and prevents access to data encrypted with expired keys without requiring manual tracking or external system coordination.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The encryption key serves as an intermediary between the data and access requests. Rather than requiring the system to actively track and delete data, the key acts as a mediator that automatically becomes invalid after a predetermined period, thereby controlling data accessibility without complex tracking mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Extent of automation

If encryption keys are programmed with expiration policies, then automatic data expiration is achieved, but additional metadata management and key validation processes are required

Engineering Contradiction:
Improveautomatic data expirationVSAvoidmetadata management complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The invention merges the expiration policy directly into the encryption key itself rather than maintaining separate metadata structures. The controller integrates key generation, expiration scheduling, and access validation into a unified process, where the key's validity period is an inherent property rather than external metadata requiring separate management.

Inventive Principle:
Principle #5Merging (Combining)

4Productivity

If expired data remains on storage devices, then storage capacity is maintained, but drive performance and endurance are reduced due to unnecessary data retention

Engineering Contradiction:
Improvedrive performanceVSAvoidstorage capacity utilization
Core Design Contradiction:
ProductivityVSQuantity of substance

Solution Approach 1:

The system converts the potential harm of data remaining on storage into a benefit by using encryption rather than physical deletion. Expired data encrypted with invalid keys occupies storage space but cannot be accessed, effectively functioning as deleted data while allowing the storage medium to be reused for new data without complex erasure or validation processes.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10756895B2Using encryption keys to manage data retention
Publication Date: 2020.08.25 SEAGATE TECH LLC
  • US10756895B2 patent drawing
  • US10756895B2 patent drawing
  • US10756895B2 patent drawing

AI summary

Systems and methods for using encryption keys to manage data retention are described. In one embodiment, the systems and methods may include receiving data such as user data from a host of the storage drive, encrypting the data using an encryption key, writing the encrypted data to the storage drive, and retaining the encrypted data on the storage drive based at least in part on a validity of the encryption key.