Hybrid Disk Drive Security Data Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Hybrid hard disk drives face increased potential for unauthorized access due to storing drive security data in both magnetic disks and non-volatile solid-state memory, allowing unauthorized users to bypass security measures by replacing the solid-state memory.
Innovation Solution
Storing an identical copy of drive security data, such as an encrypted password, in both the non-volatile solid-state storage device and the magnetic storage device, and verifying this data upon access to ensure that neither component has been replaced, with the option to also use an encrypted drive-unique identification number for additional security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If drive security data is stored in both non-volatile solid-state memory and magnetic storage device, then startup performance is improved, but security against unauthorized access deteriorates
Solution Approach 1:
The patent segments the security verification process into two independent parts: (1) storing drive security data in both non-volatile solid-state memory and magnetic storage device, and (2) verifying that both copies match before granting access. This segmentation allows the system to maintain security while enabling fast startup, as the non-volatile memory provides immediate security data without compromising overall security through the dual-verification mechanism.
Solution Approach 2:
The patent implements a feedback mechanism where the system verifies that the drive security data in non-volatile solid-state memory matches the copy in magnetic storage device before granting access. This feedback loop ensures that even though security data is stored in both locations for performance reasons, the system can detect and prevent unauthorized access attempts by confirming data integrity across both storage media.
2Loss of time
If drive security data is stored in non-volatile solid-state memory for fast access, then login time is reduced, but vulnerability to memory replacement attacks increases
Solution Approach 1:
The patent applies preliminary action by storing an identical copy of drive security data in both non-volatile solid-state memory and magnetic storage device before any access attempt occurs. This pre-established duplicate allows the system to perform fast authentication using the non-volatile memory while having a verified reference copy available for security validation, thereby preventing memory replacement attacks.
Solution Approach 2:
The patent uses copying by creating an identical duplicate of the drive security data in two separate storage locations (non-volatile solid-state memory and magnetic storage device). This copying strategy enables fast startup authentication while maintaining security through verification that both copies match, thus mitigating the risk of unauthorized memory replacement.
3Reliability
If identical copies of security data are stored in two locations, then data integrity verification is enabled, but device complexity increases
Solution Approach 1:
The patent applies universality by using the same drive security data (encrypted password or drive-unique identification number) in two different storage locations for the same security purpose. This multi-functional use of identical security data allows the system to achieve both fast authentication (through non-volatile memory) and integrity verification (through comparison with magnetic storage copy) without requiring entirely separate security mechanisms.
Data Source
AI summary
Data are accessed securely in a data storage device that includes a non-volatile solid-state storage device integrated with a magnetic storage device. An identical copy of drive security data, such as an encrypted version of a drive access password, is stored in both the non-volatile solid-state storage device and in the magnetic storage device. In response to receiving a command from a host device that results in access to the magnetic storage device, access is granted to the magnetic storage device if the copy of drive security data stored in the non-volatile solid-state storage device matches the copy of drive security data stored in the magnetic storage device. Furthermore, encrypted drive-unique identification data associated with the drive may be stored in both the non-volatile solid-state storage device and the magnetic storage device, and access is granted if both copies of the encrypted drive-unique identification data match.


