Encryption Protocol Negotiation Between Controller and Self-Encrypting Drive

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face challenges in negotiating encryption responsibilities between encryption-capable controllers and self-encrypting drives, requiring a method to determine the most suitable encryption protocol based on various criteria such as encryption strength, device capabilities, and security standards.

Innovation Solution

A system that includes a storage device with a first encryption protocol and a controller with a second encryption protocol, where a processor implements the appropriate protocol based on factors like encryption strength, topology, federal standards, virtualization support, multi-key support, and enterprise key management server support, enabling secure data transactions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system uses multiple encryption protocols with different strengths and capabilities, then security and compliance are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidencryption protocol negotiation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system changes parameters by evaluating multiple encryption protocols based on different criteria (encryption strength, FIPS certification, virtualization support, multi-key support, multi-band support, EKMS support) and selecting the optimal protocol dynamically. This allows the system to adapt security parameters to match specific requirements without hardcoding a single protocol, thereby improving security while managing complexity through structured parameter comparison.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The encryption protocol negotiation is performed autonomously by the processor without requiring manual configuration or external intervention. The system self-evaluates available protocols, compares them against required criteria, and automatically selects the most suitable protocol. This self-service approach improves security outcomes while reducing operational complexity by eliminating manual protocol configuration.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If the processor evaluates multiple encryption criteria and negotiation factors, then encryption protocol selection accuracy is improved, but processing time increases

Engineering Contradiction:
Improveprotocol selection accuracyVSAvoidnegotiation time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary evaluation by pre-identifying available encryption protocols and their capabilities before actual data encryption operations begin. The processor assesses protocol strengths, FIPS certification status, virtualization support, and other criteria in advance, establishing a ranked list of suitable protocols. This preliminary action ensures accurate protocol selection while reducing negotiation time during operational phases.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If the system supports multiple encryption protocols with different capabilities, then adaptability is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveencryption protocol compatibilityVSAvoidprotocol configuration
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system automatically performs protocol evaluation and selection without requiring user intervention or manual configuration. The processor autonomously assesses available protocols against required criteria (FIPS certification, virtualization support, multi-key support, etc.) and selects the most appropriate protocol. This self-service mechanism improves adaptability to different security requirements while maintaining ease of operation by eliminating complex manual protocol configuration.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11210430B2System and method to negotiate encryption responsibilities between an encryption capable controller and a self encrypting drive
Publication Date: 2021.12.28 DELL PROD LP
  • US11210430B2 patent drawing
  • US11210430B2 patent drawing
  • US11210430B2 patent drawing

AI summary

A system includes a storage device having a first encryption protocol, and a controller having a second encryption protocol. A processor implements the first encryption protocol or the second encryption protocol based on a strength of each encryption protocol, a topology of the system, a federal information processing standard certification status, a virtualization support, a multi-key support, a multi-band support, and an enterprise key management server support. Storage transactions may be encrypted using the implemented encryption protocol.