Failure Domain-Specific Cryptographic Keys for Storage Drive Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Storage drives face challenges with partial failures, where a portion of the drive becomes non-functional, leading to security vulnerabilities and inefficiencies in data access and management, as traditional remanufacture processes either require discarding the entire drive or leaving legacy data accessible.

Innovation Solution

Implementing failure domain-specific cryptographic keys that are uniquely associated with each failure domain within a storage drive, allowing for granular control over data access by deleting the corresponding key upon detection of a failure, thereby isolating and securing legacy data during the remanufacturing process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional remanufacture processes are used when a portion of the drive fails, then the entire drive must be discarded or legacy data remains accessible, but this leads to loss of functional drive capacity or security vulnerabilities

Engineering Contradiction:
Improvedata securityVSAvoiddrive operational capacity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The drive is divided into multiple failure domains, each with its own cryptographic key. When a failure occurs in one domain, only that specific domain's key is deleted, isolating the affected portion while preserving access to and operation of other domains. This segmentation allows the drive to maintain partial functionality while ensuring security in failed regions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different cryptographic keys are applied to different failure domains within the drive, creating local security zones. This allows security measures to be applied specifically to affected regions without impacting the entire drive, enabling selective key deletion and preserving operational capacity in unaffected domains.

Inventive Principle:
Principle #3Local quality

2Adaptability or versatility

If failure domain-specific cryptographic keys are implemented, then granular control over data access is achieved, but this increases system complexity

Engineering Contradiction:
Improvedata access control granularityVSAvoidcryptographic key management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The cryptographic key management system is segmented into multiple failure domain-specific keys rather than using a single root key for the entire drive. This segmentation enables granular control over data access by domain, allowing independent management of each failure domain's security while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

3Object-affected harmful factors

If the cryptographic key for a failed failure domain is deleted, then access to legacy data in that domain is prevented, but this requires additional key management infrastructure

Engineering Contradiction:
Improvesecurity vulnerabilities from legacy dataVSAvoidkey store and encryption engine
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The key store is organized to contain multiple failure domain-specific cryptographic keys rather than a single root key. This segmentation allows the system to delete only the specific key associated with a failed domain, preventing access to legacy data in that domain while maintaining access to data in other domains, thus reducing security vulnerabilities without requiring complete drive replacement.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11994950B2Secondary key allocation to storage drive failure domains
Publication Date: 2024.05.28 SEAGATE TECH LLC
  • US11994950B2 patent drawing
  • US11994950B2 patent drawing
  • US11994950B2 patent drawing

AI summary

Failure-domain-specific cryptographic keys for use in control of access to data within failure domains of a storage drive. A unique failure domain-specific cryptographic key may be associated with each of a plurality of failure domains in a storage drive. The failure domains may correspond to any portion of the storage media of a drive that is susceptible to failure while leaving other portions of the storage drive functional. In turn, upon detection of a condition associated with a failure (e.g., an actual or predicted failure) of a failure domain, the associated failure domain-specific cryptographic key may be deleted to preclude further access to data in the failed failure domain. Deletion of the failure domain-specific cryptographic key may be before or after data in the failed failure domain is rebuilt in another portion of a storage drive that is functional.