Secure Pluggable Flash Storage via DADS Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Pluggable flash storage devices face security vulnerabilities due to unauthorized access and data corruption during read/write operations, which can lead to system malfunction or crash, especially when power is lost or the storage controller restarts.

Innovation Solution

Implementing a Device Authentication and Data Security (DADS) component that authenticates the storage device and users/storage controllers using predetermined signatures and access keys, ensuring secure communication by encrypting and compressing data, and managing sessions to prevent unauthorized access and data corruption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the pluggable flash storage device is made removable and rewriteable for flexible data storage, then the ease of operation and adaptability are improved, but the security and reliability deteriorate due to unauthorized access and data corruption risks

Engineering Contradiction:
Improveremovability and rewriteabilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary authentication of the storage device and user before allowing any read/write operations. The DADS component verifies device signatures and user credentials in advance, establishing secure access rights before data operations commence, thereby preventing unauthorized access while maintaining ease of use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The DADS (Device Authentication and Data Security) component acts as an intermediary between the user/storage controller and the pluggable flash storage device. It mediates all read/write operations by verifying device signatures, authenticating users, and managing session keys, thus ensuring data security without compromising the removability and ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and encryption mechanisms are added to secure read/write operations, then the data security is improved, but the device complexity and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The DADS component is designed as a multi-functional module that combines device signature verification, user authentication, session management, and encryption/decryption operations. By consolidating these security functions into a single universal component, the system achieves high data security while minimizing the increase in overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The authentication and encryption mechanisms are automatically executed by the DADS component without requiring manual user intervention. The system self-manages session keys, automatically verifies device signatures, and handles encryption/decryption processes, thereby reducing the perceived complexity for users while maintaining robust security.

Inventive Principle:
Principle #25Self-service

3Reliability

If session management and authentication protocols are implemented, then the prevention of unauthorized access is improved, but the processing time and operational complexity increase

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs authentication and session establishment as preliminary actions before any data operations. By pre-verifying device signatures and user credentials, and establishing session keys in advance, the system minimizes processing delays during actual read/write operations, thus preventing unauthorized access while reducing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once authentication is successful and a session is established, the DADS component maintains continuous secure operations without requiring repeated authentication for subsequent read/write operations. This continuity approach ensures unauthorized access prevention while minimizing the time penalty of authentication protocols.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9721122B2Method and system for performing secure I/O operation in a pluggable flash storage device
Publication Date: 2017.08.01 WIPRO LTD
  • US9721122B2 patent drawing
  • US9721122B2 patent drawing
  • US9721122B2 patent drawing

AI summary

The present disclosure relates to a method and a system for performing secure read/write operations in the pluggable flash storage device. In one embodiment, a request for at least writing and reading of data in/from the pluggable flash storage device is received. Upon receiving the request for writing data, the storage device is authenticated based on a predetermined signature of the pluggable flash storage device. Upon authenticating the storage device, the at least one of user and the storage controller who made the request is also authenticated and write operation is performed based on successful authentication of the at least one of the user and the storage controller. By way of establishing secure communication between the storage device and the user or the storage controller during the read/write operation the hacking of the data in the storage device or use of the storage device with wrong intent is avoided.