Flash Drive Encryption for Full Disk Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Full Disk Encryption Drives (FDEs) face a trade-off between system speed and security, as comprehensive encryption can slow down the system and using external flash memory as a non-volatile cache introduces a vulnerability if critical files are cached without being written to the hard drive.

Innovation Solution

Implementing a system where data is encrypted as it enters the flash drive and decrypted as it leaves, with the flash drive logically bound to the hard disk using the same encryption key, ensuring sensitive data remains encrypted and synchronized with the hard disk, even if moved to another system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full disk encryption is implemented, then security is improved, but system speed deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidsystem speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent segments the storage system into two parts: encrypted hard drive storage and unencrypted flash memory cache. By dividing the data storage function between these two components, the system achieves both security (encrypted data on hard drive) and speed (unencrypted data in flash cache), resolving the contradiction between security and system speed.

Inventive Principle:
Principle #1Segmentation

2Speed

If external flash memory is used as non-volatile cache, then system speed is improved, but security deteriorates due to vulnerable cached files

Engineering Contradiction:
Improvesystem speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent extracts the caching function from the encrypted hard drive system and places it in separate unencrypted flash memory. This extraction allows the cache to operate at high speed without encryption overhead, while the main storage remains secure through encryption, thus resolving the security-speed contradiction.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If data is cached in flash memory without encryption, then system speed is improved, but data vulnerability increases

Engineering Contradiction:
Improvesystem performanceVSAvoiddata vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different quality characteristics to different parts of the storage system: the flash memory cache is designed for high performance with unencrypted data, while the hard drive storage is designed for security with encrypted data. This local differentiation of quality attributes allows each component to optimize its function while mitigating the overall system's weaknesses.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9323956B2Merging external NVRAM with full disk encryption
Publication Date: 2016.04.26 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US9323956B2 patent drawing
  • US9323956B2 patent drawing
  • US9323956B2 patent drawing

AI summary

Methods and arrangements for managing a flash drive, hard disk, or connection between the two, in a manner to ensure that sensitive data is not decrypted at any time when it would be vulnerable. Accordingly, in a first implementation, the data may preferably be encrypted as it first goes into a flash drive and decrypted when it comes out of the flash drive. In another implementation, the flash drive may be logically bound to the hard disk, so that they would both use the same encryption key. In yet another implementation, if a hard disk is moved to another system, then the flash drive may also preferably be simultaneously moved.