MSED Controller Rekey Authentication for Secure Password Changes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In remote managed self-encrypting drive (MSED) encryption, there is a lack of secondary authentication for controller password settings, enabling anyone to change or disable the password without authorization, leading to potential data theft risks when the key manager service is inactive.

Innovation Solution

Implementing a secondary authentication mechanism using a first and second level credential system, where the first level credential allows access to data and the second level credential enables configuration changes, ensuring that only authorized users can modify controller passwords or rekey operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote MSED encryption is enabled without secondary authentication, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improvecontroller password settingsVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments authentication into two distinct levels: first level credential authentication for data access and second level credential authentication for configuration changes. This segmentation allows the system to provide different authentication requirements for different operations, improving ease of operation for data access while maintaining strong security for password settings and rekey operations.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If anyone can change controller password without authentication, then ease of operation is improved, but harmful factors increase

Engineering Contradiction:
Improvepassword modificationVSAvoiddata theft risk
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by requiring second level credential authentication before allowing controller password changes, rekey operations, or password enable/disable actions. This preliminary security measure prevents unauthorized configuration changes that could lead to data theft, while still allowing authorized users to modify passwords when needed.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If KMS is inactive and master key is stored in NVRAM, then reliability is improved, but security deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent adds another dimension of security by introducing a second level credential that operates independently of the KMS status. When KMS is inactive and the master key is stored in NVRAM, the second level credential authentication provides an additional layer of protection for password settings and rekey operations, preventing unauthorized access even when the first level authentication is compromised.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20260046135A1Secondary authentication for controller password settings and rekey in remote MSED encryption configuration
Publication Date: 2026.02.12 MICROCHIP TECHNOLOGY INC
  • US20260046135A1 patent drawing
  • US20260046135A1 patent drawing
  • US20260046135A1 patent drawing

AI summary

A method comprising: enabling a secondary authentication password via a controller during remote managed self-encrypting drive encryption; storing the secondary authentication credential in a memory of the controller; and allowing a change of remote managed self-encrypting drive settings when authentication via the secondary authentication credential is successful. A device comprising: a memory to store the secondary authentication credential; and a controller to: enable a secondary authentication credential during remote managed self-encrypting drive encryption; and allow a change of remote managed self-encrypting drive settings when authentication via the secondary authentication credential is successful.