Local Security Management for Data Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management processes for data storage devices rely on host platforms, making them vulnerable to malware attacks and limiting scalability due to the need for specific hardware components like TPMs, which reduces trust in security solutions and increases susceptibility to stealthy malware threats.

Innovation Solution

Implementing local security management within data storage devices using additional hardware and software logic, such as processing cores, accelerators, and secure storage regions, to authorize access, scan for malware, and perform authentication independently of the host platform, enhancing malware detection and recovery capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security management processes are performed in a host platform, then security management for the storage device can be maintained, but compromising the security state of the host platform results in compromising security management for the storage device

Engineering Contradiction:
Improvesecurity management reliabilityVSAvoidsusceptibility to malware attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides security management functionality into separate components: host platform security management processes and storage device local security management processes. The storage device includes its own processor and memory to independently execute security management code, scanning for malware and managing security credentials without relying on the host platform's security state.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted platform module (TPM) or secure enclave as an intermediary security management component. This intermediary maintains security credentials and executes security verification independently, acting as a mediator between the storage device and host platform while resisting malware attacks that compromise the host OS.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security management capabilities are updated in host platform chipsets, then security improvements can be implemented, but scalability is limited by the install base of host chipsets that already have required hardware

Engineering Contradiction:
Improvesecurity improvement capabilityVSAvoidscalability across different platforms
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements universal security management functionality within the storage device that can operate across different host platform architectures. The storage device includes its own processor and security management code that can execute independently of host platform-specific hardware, enabling the same security solution to be deployed across diverse platforms including PCs, servers, and embedded systems.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The storage device performs self-service security management by maintaining its own security credentials, executing local malware scanning, and managing authentication independently. This self-service capability eliminates dependency on host platform hardware and software configurations, enabling broad scalability across different computing platforms.

Inventive Principle:
Principle #25Self-service

3Reliability

If additional hardware and software logic are added to data storage devices for local security management, then malware detection and recovery capabilities are enhanced, but device complexity increases

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidstorage device complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security management functionality directly into the storage device's existing processor and memory resources. Rather than adding completely separate security hardware, the storage device utilizes its built-in processing capabilities to execute security management code and perform malware scanning, combining storage and security functions within a single device architecture.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9064116B2Techniques for security management provisioning at a data storage device
Publication Date: 2015.06.23 SK HYNIX NAND PRODUCT SOLUTIONS CORP
  • US9064116B2 patent drawing
  • US9064116B2 patent drawing
  • US9064116B2 patent drawing

AI summary

Techniques for a data storage device to locally implement security management functionality. In an embodiment, a security management process of the data storage device is to determine whether an access to non-volatile media of the data storage device is authorized. In certain embodiments, the data storage device is to restrict access to a secure region of the non-volatile storage media, the secure region to store information used and/or generated by a security management process of the data storage device.