Secure Pluggable Flash Storage Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Pluggable flash storage devices are vulnerable to unauthorized access and hacking, which can lead to data corruption or loss, causing SAN storage controllers to malfunction or crash, as existing security measures are inadequate for ensuring secure read/write operations.

Innovation Solution

A method and system for performing secure read/write operations in pluggable flash storage devices, involving authentication of the device, user, and storage controller using predetermined access keys and signatures, along with encryption and compression of data, to establish secure communication and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If pluggable flash storage device is made accessible for read/write operations, then productivity and ease of operation are improved, but security and reliability deteriorate due to unauthorized access and hacking risks

Engineering Contradiction:
Improveread/write operation accessibilityVSAvoiddata security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements authentication of the storage device, user, and storage controller before allowing any read/write operations. This preliminary security check ensures that only authorized entities can access the storage device, preventing unauthorized access and data corruption while maintaining productivity for legitimate users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an authentication mechanism as an intermediary layer between the storage device and access requests. This intermediary verifies the authenticity of the storage device using a predetermined signature and authenticates users and storage controllers using access keys, thereby securing data transmission without hindering legitimate operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication and encryption mechanisms are implemented, then data security and reliability are improved, but device complexity and processing time increase

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication process into distinct components: storage device authentication using a predetermined signature, user authentication using access keys, and storage controller authentication. This segmentation allows each authentication step to be handled independently, reducing overall system complexity while maintaining comprehensive security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication processes are performed preliminarily before actual data operations. By completing authentication upfront, the system establishes security without adding complexity to the core data read/write operations, thereby maintaining efficiency while ensuring reliability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If data is encrypted and compressed before storage, then data security and integrity are improved, but processing time and computational resources increase

Engineering Contradiction:
Improvedata integrityVSAvoiddata processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies encryption and compression to data before storage as a preliminary action. This ensures data integrity and security is established upfront, allowing faster retrieval and processing during read operations since the security framework is already in place. The one-time processing overhead is offset by subsequent faster access times.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3054398B1Method and system for performing secure I/O operation in a pluggable flash storage device
Publication Date: 2018.09.12 WIPRO LTD
  • EP3054398B1 patent drawingFigure 1
  • EP3054398B1 patent drawingFigure 2
  • EP3054398B1 patent drawingFigure 3a~3b

AI summary

The present disclosure relates to a method and a system for performing secure read/write operations in the pluggable flash storage device. In one embodiment, a request for at least writing and reading of data in/from the pluggable flash storage device is received. Upon receiving the request for writing data, the storage device is authenticated based on a predetermined signature of the pluggable flash storage device. Upon authenticating the storage device, the at least one of user and the storage controller who made the request is also authenticated and write operation is performed based on successful authentication of the at least one of the user and the storage controller. By way of establishing secure communication between the storage device and the user or the storage controller during the read/write operation the hacking of the data in the storage device or use of the storage device with wrong intent is avoided.