Hardware Root of Trust for Secure Encrypted Drive Access Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure and self-encrypting drive (SED) systems face challenges in protecting encryption key updates, especially when the system's physical state is not trusted, leading to potential interceptions and compromised confidentiality during remote control and maintenance.

Innovation Solution

A system combining Hardware and Software Roots of Trust (RoT), multi-level system monitoring, and multi-dimensional machine learning for secure data protection, which includes a Hardware Root of Trust (HRoT) device that validates integrity, authenticates devices, and takes control in case of security risks, providing a Trusted Execution Environment and blocking unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote control and maintenance of SED devices is implemented, then accessibility and ease of operation are improved, but security and reliability deteriorate due to potential interception of encryption key updates

Engineering Contradiction:
Improveremote control accessibilityVSAvoidsecurity of encryption key updates
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Hardware Root of Trust (HRoT) device as an intermediary between the computing device and storage device. The HRoT validates the integrity of the computing device and authentication credentials before allowing control operations, acting as a trusted mediator that prevents unauthorized access while enabling remote operation. This resolves the contradiction by adding a security layer that doesn't block legitimate remote access but blocks malicious interception attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary validation of the computing device's integrity and authentication credentials through the HRoT before allowing any remote control operations or encryption key updates. By validating the system state in advance and establishing a trusted execution environment beforehand, the system ensures that subsequent remote operations are secure, thus maintaining both accessibility and security.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If the system physically hosting the SED is not trusted, then adaptability is improved (system can operate in untrusted environments), but security deteriorates (any updates to the drive cannot be trusted)

Engineering Contradiction:
Improveability to operate in untrusted environmentsVSAvoidtrustworthiness of drive updates
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The HRoT device serves as a trusted intermediary that operates independently of the host system's trustworthiness. It validates authentication credentials and controls access to the storage device based on cryptographic proofs rather than trusting the host system. This allows the system to operate in untrusted environments while maintaining security through the HRoT's independent verification processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent extracts the trust anchor from the host system by implementing a separate Hardware Root of Trust device. The HRoT contains the trusted execution environment and validation logic independent of the potentially untrusted host system. By separating the trust function from the host system, the patent enables operation in untrusted environments while ensuring that critical security functions remain trustworthy.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If HRoT device takes over control of storage device upon detecting security risk, then security is improved, but ease of operation deteriorates due to automatic blocking of communication

Engineering Contradiction:
Improvesecurity response to threatsVSAvoidcommunication availability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The HRoT device autonomously monitors system integrity and automatically takes control of the storage device when security risks are detected, without requiring human intervention. The system self-manages security responses by validating threats and executing appropriate countermeasures (such as blocking communication or locking the storage device), thus improving security response while minimizing the need for operational intervention.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The HRoT device is pre-configured with security policies and thresholds that automatically trigger protective actions when specific risk conditions are met. By establishing predetermined response protocols in advance, the system can quickly counteract security threats without requiring real-time human decision-making, thus improving security response time while maintaining operational simplicity through automated rule-based responses.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11513698B2Root of trust assisted access control of secure encrypted drives
Publication Date: 2022.11.29 NIGHTWING GROUP LLC
  • US11513698B2 patent drawing
  • US11513698B2 patent drawing
  • US11513698B2 patent drawing

AI summary

A system for data protection includes a computing device comprising a processor, a Hardware Root of Trust (HRoT) module and a storage device. The HRoT device is configured to: validate integrity of the computing device; authenticate the computing device to communicate with the storage device; and take over control of storage device access and behaviour whenever suspicious or unauthorized data access from local or remote computing devices is detected. The HRoT device is further configured to, in response to detecting a security risk to at least one of the computing device and the storage device, block communication of the storage device.