Magnetic Recording Medium Encryption Key Update

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional Full Disk Encryption (FDE) systems do not allow users to easily change the encryption key, leaving users vulnerable if the initial encryption key is compromised, as they must continue using the pre-set key, potentially leading to data security risks.

Innovation Solution

A system and method for re-encrypting data on a magnetic recording medium by setting a pair of updating source and reserved areas, reading and decrypting data using a first encryption key, and re-encrypting it with a new key, repeating the process until all data is updated, allowing for easy and efficient key changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Full Disk Encryption is implemented with a pre-set encryption key, then data security is improved, but the ability to change the encryption key is lost

Engineering Contradiction:
Improvedata securityVSAvoidkey change capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent divides the magnetic recording medium into multiple areas: a first area containing data encrypted with the first encryption key, and a second area serving as a reserved area for re-encrypting data. This segmentation allows the system to process encryption key changes by handling data in distinct zones, enabling the transition from the first encryption key to the second encryption key without compromising the entire dataset.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary actions by first reading data from the first area, then re-encrypting it with the second encryption key before writing to the second area. This preliminary processing of data allows the system to prepare encrypted data in advance during key changes, ensuring that all data is updated to the new encryption key without requiring system downtime or compromising security during the transition.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If all data is re-encrypted with a new key, then security against key compromise is improved, but the time required for key change increases

Engineering Contradiction:
Improvesecurity against key compromiseVSAvoidkey change time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the data processing into two distinct areas: the first area for reading data encrypted with the old key, and the second area for writing data encrypted with the new key. This segmentation enables parallel processing and avoids the need to lock the entire storage medium during key changes, significantly reducing the time required while ensuring complete data re-encryption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary reading of data from the first area before initiating the re-encryption process. By preparing the data in advance and using the reserved second area for temporary storage during re-encryption, the system minimizes the time data is locked and ensures that the key change process can proceed efficiently without delaying user access.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If encryption key change is implemented, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveencryption key change capabilityVSAvoidencryption system complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent introduces a clear segmentation of the magnetic recording medium into a first area for existing encrypted data and a second area as a reserved area for re-encryption operations. This segmentation provides a structured approach to key changes, organizing the complex process into manageable zones that simplify the implementation and control of encryption key transitions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The second area acts as an intermediary zone between the first area (containing data encrypted with the first key) and the final encrypted storage. This intermediary reserved area allows the system to temporarily hold and process data during key changes, simplifying the overall mechanism by providing a dedicated space for re-encryption operations without interfering with the original data structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8037320B2Magnetic recording medium encryption
Publication Date: 2011.10.11 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8037320B2 patent drawing
  • US8037320B2 patent drawing
  • US8037320B2 patent drawing

AI summary

Systems and methods for easily and at high speed re-encrypting data recorded on a magnetic recording medium when the data is encrypted using an encryption key and the encryption key is changed. A track where effective user data is not recorded is set as a first reserved track, then data is read out from the first updating source track and decrypted using a first encryption key KEY 1, which is reencrypted using a second encryption key KEY 2 and recorded in the first reserved track, next, the first updating source track is set as a second reserved track, and a second updating source track is set, and the encryption key is updated by repeating these steps until all tracks to be subjected to the key updating processing have been subjected to the key updating processing.