Encryption Key Data Retention Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data retention policies are difficult to enforce at both the storage drive and system levels, leading to expired data remaining on storage devices, which poses security and legal risks and wastes storage capacity, as existing systems fail to ensure data is properly destroyed when it expires.
Innovation Solution
The use of encryption keys with associated retention policies, where data is encrypted and retained based on the validity of the encryption key, automatically marking and expiring data when the key expires, ensuring data is discarded during the recycling process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is retained on storage drive without automatic expiration enforcement, then storage capacity is utilized, but security risks and legal compliance issues arise from expired data remaining on devices
Solution Approach 1:
The system performs preliminary actions by encrypting data with time-limited keys before storage and pre-scheduling key expiration. The controller automatically expires encryption keys after predetermined time periods, ensuring expired data is automatically rendered inaccessible without requiring manual intervention or external verification.
Solution Approach 2:
The invention extracts the access control mechanism from traditional permission-based systems and replaces it with encryption-based access control. By separating the encryption key from the data and controlling key availability through automatic expiration, the system removes the ability to access expired data while the data itself remains on the storage medium.
2Reliability
If manual data deletion processes are used to enforce retention policies, then data can be removed when needed, but the complexity of tracking and deleting expired data across the system increases
Solution Approach 1:
The system implements self-service by automatically managing the entire data expiration lifecycle. The controller monitors encryption key validity periods, automatically expires keys when time limits are reached, and prevents access to data encrypted with expired keys without requiring manual tracking or external system coordination.
Solution Approach 2:
The encryption key serves as an intermediary between the data and access requests. Rather than requiring the system to actively track and delete data, the key acts as a mediator that automatically becomes invalid after a predetermined period, thereby controlling data accessibility without complex tracking mechanisms.
3Extent of automation
If encryption keys are programmed with expiration policies, then automatic data expiration is achieved, but additional metadata management and key validation processes are required
Solution Approach 1:
The invention merges the expiration policy directly into the encryption key itself rather than maintaining separate metadata structures. The controller integrates key generation, expiration scheduling, and access validation into a unified process, where the key's validity period is an inherent property rather than external metadata requiring separate management.
4Productivity
If expired data remains on storage devices, then storage capacity is maintained, but drive performance and endurance are reduced due to unnecessary data retention
Solution Approach 1:
The system converts the potential harm of data remaining on storage into a benefit by using encryption rather than physical deletion. Expired data encrypted with invalid keys occupies storage space but cannot be accessed, effectively functioning as deleted data while allowing the storage medium to be reused for new data without complex erasure or validation processes.
Data Source
AI summary
Systems and methods for using encryption keys to manage data retention are described. In one embodiment, the systems and methods may include receiving data such as user data from a host of the storage drive, encrypting the data using an encryption key, writing the encrypted data to the storage drive, and retaining the encrypted data on the storage drive based at least in part on a validity of the encryption key.


