MSED Controller Rekey Authentication for Secure Password Changes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In remote managed self-encrypting drive (MSED) encryption, there is a lack of secondary authentication for controller password settings, enabling anyone to change or disable the password without authorization, leading to potential data theft risks when the key manager service is inactive.
Innovation Solution
Implementing a secondary authentication mechanism using a first and second level credential system, where the first level credential allows access to data and the second level credential enables configuration changes, ensuring that only authorized users can modify controller passwords or rekey operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remote MSED encryption is enabled without secondary authentication, then ease of operation is improved, but security deteriorates
Solution Approach 1:
The patent segments authentication into two distinct levels: first level credential authentication for data access and second level credential authentication for configuration changes. This segmentation allows the system to provide different authentication requirements for different operations, improving ease of operation for data access while maintaining strong security for password settings and rekey operations.
2Ease of operation
If anyone can change controller password without authentication, then ease of operation is improved, but harmful factors increase
Solution Approach 1:
The patent applies preliminary anti-action by requiring second level credential authentication before allowing controller password changes, rekey operations, or password enable/disable actions. This preliminary security measure prevents unauthorized configuration changes that could lead to data theft, while still allowing authorized users to modify passwords when needed.
3Reliability
If KMS is inactive and master key is stored in NVRAM, then reliability is improved, but security deteriorates
Solution Approach 1:
The patent adds another dimension of security by introducing a second level credential that operates independently of the KMS status. When KMS is inactive and the master key is stored in NVRAM, the second level credential authentication provides an additional layer of protection for password settings and rekey operations, preventing unauthorized access even when the first level authentication is compromised.
Data Source
AI summary
A method comprising: enabling a secondary authentication password via a controller during remote managed self-encrypting drive encryption; storing the secondary authentication credential in a memory of the controller; and allowing a change of remote managed self-encrypting drive settings when authentication via the secondary authentication credential is successful. A device comprising: a memory to store the secondary authentication credential; and a controller to: enable a secondary authentication credential during remote managed self-encrypting drive encryption; and allow a change of remote managed self-encrypting drive settings when authentication via the secondary authentication credential is successful.


