Flash Drive Encryption for Full Disk Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Full Disk Encryption Drives (FDEs) face a trade-off between system speed and security, as comprehensive encryption can slow down the system and using external flash memory as a non-volatile cache introduces a vulnerability if critical files are cached without being written to the hard drive.
Innovation Solution
Implementing a system where data is encrypted as it enters the flash drive and decrypted as it leaves, with the flash drive logically bound to the hard disk using the same encryption key, ensuring sensitive data remains encrypted and synchronized with the hard disk, even if moved to another system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If full disk encryption is implemented, then security is improved, but system speed deteriorates
Solution Approach 1:
The patent segments the storage system into two parts: encrypted hard drive storage and unencrypted flash memory cache. By dividing the data storage function between these two components, the system achieves both security (encrypted data on hard drive) and speed (unencrypted data in flash cache), resolving the contradiction between security and system speed.
2Speed
If external flash memory is used as non-volatile cache, then system speed is improved, but security deteriorates due to vulnerable cached files
Solution Approach 1:
The patent extracts the caching function from the encrypted hard drive system and places it in separate unencrypted flash memory. This extraction allows the cache to operate at high speed without encryption overhead, while the main storage remains secure through encryption, thus resolving the security-speed contradiction.
3Productivity
If data is cached in flash memory without encryption, then system speed is improved, but data vulnerability increases
Solution Approach 1:
The patent applies different quality characteristics to different parts of the storage system: the flash memory cache is designed for high performance with unencrypted data, while the hard drive storage is designed for security with encrypted data. This local differentiation of quality attributes allows each component to optimize its function while mitigating the overall system's weaknesses.
Data Source
AI summary
Methods and arrangements for managing a flash drive, hard disk, or connection between the two, in a manner to ensure that sensitive data is not decrypted at any time when it would be vulnerable. Accordingly, in a first implementation, the data may preferably be encrypted as it first goes into a flash drive and decrypted when it comes out of the flash drive. In another implementation, the flash drive may be logically bound to the hard disk, so that they would both use the same encryption key. In yet another implementation, if a hard disk is moved to another system, then the flash drive may also preferably be simultaneously moved.


