Kill Switch Encryption Key for Secure System Decommissioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current information handling systems face challenges in securely decommissioning data, as conventional security measures like firewalls and password-based logins can be bypassed, and manual erasure processes are costly, time-consuming, and prone to human errors, with residual data remaining on storage media despite attempted deletion.

Innovation Solution

Implementing a single encryption key erasure (kill switch) command within an information handling system, where a service processor establishes and manages a kill switch encryption key (KSEK) to encrypt and decrypt data, ensuring only authorized access and permanent deletion of the KSEK upon verified decommission requests, thereby preventing future access to encrypted data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security measures (firewall, password-based logins) are used to protect customer data, then unauthorized access is prevented, but skilled hackers can bypass these measures and access stored data from NVRAMs

Engineering Contradiction:
Improvedata securityVSAvoiddata breach risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an encryption key management system as an intermediary layer between the stored data and potential attackers. The encryption keys are stored in a separate secure location (key management system) rather than with the data itself, creating a mediator that controls access to the data. This resolves the contradiction by adding a security layer that even skilled hackers cannot bypass without compromising the key management system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security architecture by separating data storage from key storage. Customer data is stored in NVRAMs while encryption keys are maintained in a dedicated key management system. This segmentation ensures that even if data is accessed, it remains encrypted and inaccessible without the corresponding keys, thereby improving data security while maintaining the ability to protect against sophisticated attacks.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual erasure processes are used to delete customer data during decommissioning, then data can be removed from storage devices, but the process is costly, time-consuming, and prone to human errors with residual data remaining

Engineering Contradiction:
Improvedata erasure completenessVSAvoiddecommissioning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service through automated encryption key deletion. When decommissioning is required, the system automatically deletes the encryption keys from the key management system, which in turn automatically decrypts and renders all associated customer data inaccessible. This eliminates the need for manual erasure operations, reducing decommissioning time and eliminating human errors while ensuring complete data protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent applies preliminary action by encrypting all customer data before storing it in NVRAMs during the provisioning phase. This preliminary encryption ensures that when decommissioning occurs, the data is already protected by the encryption mechanism. The key deletion during decommissioning automatically applies the preliminary encryption protection, eliminating the need for manual erasure operations and reducing decommissioning time.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If flash storage media with wear-leveling technology is used, then data can be stored efficiently, but erasure of logical device does not result in erasure of entire physical device, leaving residual data accessible

Engineering Contradiction:
Improvedata storage efficiencyVSAvoiddata erasure security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent uses encryption as an intermediary mechanism that operates independently of the physical storage media characteristics. The encryption keys serve as a mediator that controls access to data regardless of whether the underlying flash storage has been physically erased. This resolves the contradiction by providing a security mechanism that is not affected by wear-leveling technology's inability to fully erase physical media.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent substitutes the mechanical erasure process with a cryptographic solution. Instead of relying on physical erasure of flash storage media (which is ineffective due to wear-leveling), the system uses encryption and key deletion to achieve data protection. This substitution resolves the contradiction by replacing the ineffective mechanical erasure approach with a cryptographic approach that is not impacted by storage media characteristics.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8938626B2Single command functionality for providing data security and preventing data access within a decommissioned information handling system
Publication Date: 2015.01.20 DELL PROD LP
  • US8938626B2 patent drawing
  • US8938626B2 patent drawing
  • US8938626B2 patent drawing

AI summary

A computer-implemented method comprises a service processor: establishing a kill switch encryption key (KSEK) to provide data security for data within storage devices of configurable components within a system; automatically encrypting, with the KSEK, data that is written to one of the storage devices; configuring the configurable components to prevent access to the stored data unless a valid copy of the KSEK is received from the service processor along with the request for the data; automatically decrypting, with the KSEK, the KSEK-encrypted data that is read from storage device; and in response to receiving a verified request to decommission the system, performing the decommissioning by deleting/erasing the KSEK from a secure storage at which the only instance of the KSEK is maintained. Deletion of the KSEK results in a permanent loss of access to the stored encrypted data within the system because the stored encrypted data cannot be decrypted without the KSEK.