Secure Pluggable Flash Storage via DADS Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Pluggable flash storage devices face security vulnerabilities due to unauthorized access and data corruption during read/write operations, which can lead to system malfunction or crash, especially when power is lost or the storage controller restarts.
Innovation Solution
Implementing a Device Authentication and Data Security (DADS) component that authenticates the storage device and users/storage controllers using predetermined signatures and access keys, ensuring secure communication by encrypting and compressing data, and managing sessions to prevent unauthorized access and data corruption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the pluggable flash storage device is made removable and rewriteable for flexible data storage, then the ease of operation and adaptability are improved, but the security and reliability deteriorate due to unauthorized access and data corruption risks
Solution Approach 1:
The system performs preliminary authentication of the storage device and user before allowing any read/write operations. The DADS component verifies device signatures and user credentials in advance, establishing secure access rights before data operations commence, thereby preventing unauthorized access while maintaining ease of use.
Solution Approach 2:
The DADS (Device Authentication and Data Security) component acts as an intermediary between the user/storage controller and the pluggable flash storage device. It mediates all read/write operations by verifying device signatures, authenticating users, and managing session keys, thus ensuring data security without compromising the removability and ease of operation.
2Reliability
If authentication and encryption mechanisms are added to secure read/write operations, then the data security is improved, but the device complexity and processing time increase
Solution Approach 1:
The DADS component is designed as a multi-functional module that combines device signature verification, user authentication, session management, and encryption/decryption operations. By consolidating these security functions into a single universal component, the system achieves high data security while minimizing the increase in overall device complexity.
Solution Approach 2:
The authentication and encryption mechanisms are automatically executed by the DADS component without requiring manual user intervention. The system self-manages session keys, automatically verifies device signatures, and handles encryption/decryption processes, thereby reducing the perceived complexity for users while maintaining robust security.
3Reliability
If session management and authentication protocols are implemented, then the prevention of unauthorized access is improved, but the processing time and operational complexity increase
Solution Approach 1:
The system performs authentication and session establishment as preliminary actions before any data operations. By pre-verifying device signatures and user credentials, and establishing session keys in advance, the system minimizes processing delays during actual read/write operations, thus preventing unauthorized access while reducing time loss.
Solution Approach 2:
Once authentication is successful and a session is established, the DADS component maintains continuous secure operations without requiring repeated authentication for subsequent read/write operations. This continuity approach ensures unauthorized access prevention while minimizing the time penalty of authentication protocols.
Data Source
AI summary
The present disclosure relates to a method and a system for performing secure read/write operations in the pluggable flash storage device. In one embodiment, a request for at least writing and reading of data in/from the pluggable flash storage device is received. Upon receiving the request for writing data, the storage device is authenticated based on a predetermined signature of the pluggable flash storage device. Upon authenticating the storage device, the at least one of user and the storage controller who made the request is also authenticated and write operation is performed based on successful authentication of the at least one of the user and the storage controller. By way of establishing secure communication between the storage device and the user or the storage controller during the read/write operation the hacking of the data in the storage device or use of the storage device with wrong intent is avoided.


