Local Security Management for Data Storage Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security management processes for data storage devices rely on host platforms, making them vulnerable to malware attacks and limiting scalability due to the need for specific hardware components like TPMs, which reduces trust in security solutions and increases susceptibility to stealthy malware threats.
Innovation Solution
Implementing local security management within data storage devices using additional hardware and software logic, such as processing cores, accelerators, and secure storage regions, to authorize access, scan for malware, and perform authentication independently of the host platform, enhancing malware detection and recovery capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security management processes are performed in a host platform, then security management for the storage device can be maintained, but compromising the security state of the host platform results in compromising security management for the storage device
Solution Approach 1:
The patent divides security management functionality into separate components: host platform security management processes and storage device local security management processes. The storage device includes its own processor and memory to independently execute security management code, scanning for malware and managing security credentials without relying on the host platform's security state.
Solution Approach 2:
The patent introduces a trusted platform module (TPM) or secure enclave as an intermediary security management component. This intermediary maintains security credentials and executes security verification independently, acting as a mediator between the storage device and host platform while resisting malware attacks that compromise the host OS.
2Reliability
If security management capabilities are updated in host platform chipsets, then security improvements can be implemented, but scalability is limited by the install base of host chipsets that already have required hardware
Solution Approach 1:
The patent implements universal security management functionality within the storage device that can operate across different host platform architectures. The storage device includes its own processor and security management code that can execute independently of host platform-specific hardware, enabling the same security solution to be deployed across diverse platforms including PCs, servers, and embedded systems.
Solution Approach 2:
The storage device performs self-service security management by maintaining its own security credentials, executing local malware scanning, and managing authentication independently. This self-service capability eliminates dependency on host platform hardware and software configurations, enabling broad scalability across different computing platforms.
3Reliability
If additional hardware and software logic are added to data storage devices for local security management, then malware detection and recovery capabilities are enhanced, but device complexity increases
Solution Approach 1:
The patent merges security management functionality directly into the storage device's existing processor and memory resources. Rather than adding completely separate security hardware, the storage device utilizes its built-in processing capabilities to execute security management code and perform malware scanning, combining storage and security functions within a single device architecture.
Data Source
AI summary
Techniques for a data storage device to locally implement security management functionality. In an embodiment, a security management process of the data storage device is to determine whether an access to non-volatile media of the data storage device is authorized. In certain embodiments, the data storage device is to restrict access to a secure region of the non-volatile storage media, the secure region to store information used and/or generated by a security management process of the data storage device.


