Portable Storage Device Trusted Host Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current portable storage devices require manual effort and matching security software at both ends for secure data transfer, making them inconvenient and impractical for secure data access, leading to users often opting for unsecured data transfer due to the conflict between security and convenience.

Innovation Solution

A portable storage device that automates unlocking when mounted on a trusted host device, using mechanisms such as trusted host lists, cookie files, and cryptoprocessors to allow access without requiring user input, while maintaining the option for conventional unlocking on untrusted devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual password entry is required for secure data access, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically authenticating trusted host devices during the mounting process before data access is requested. The portable storage device identifies the host device and verifies trust status in advance, eliminating the need for manual password entry during subsequent data operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The portable storage device provides self-service authentication by automatically managing the trusted host verification process. The device maintains internal records of trusted hosts and performs automated authentication without requiring user intervention, allowing the system to serve itself in the security verification process.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If automated unlocking is implemented for trusted devices, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improveease of operationVSAvoiddevice complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication during the device mounting phase, storing trust relationships in advance. This preliminary action eliminates the need for complex real-time authentication protocols during data access, as the trust status is already determined and stored.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The automated authentication feature is selectively applied only to trusted host devices, while maintaining manual password requirements for untrusted devices. This local quality approach allows the system to implement complexity only where security risks are minimized, rather than uniformly across all access scenarios.

Inventive Principle:
Principle #3Local quality

3Reliability

If security software must be installed on both source and target computers, then security is improved, but ease of manufacture and deployment deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of deployment
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The security functionality is extracted from the host computer software and relocated to the portable storage device itself. The device contains its own authentication logic and trusted host management capabilities, eliminating the requirement for matching security software installations on connected computers.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable storage device is designed with universal compatibility to work with any host device that meets basic system requirements. The device handles all security operations independently, allowing it to function across different operating systems and hardware platforms without requiring platform-specific security software.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8745409B2System and method for securing portable data
Publication Date: 2014.06.03 SANDISK ISRAEL LTD
  • US8745409B2 patent drawing
  • US8745409B2 patent drawing
  • US8745409B2 patent drawing

AI summary

A data storage device that can be reversibly associated with one or more of a plurality of hosts. A “trusted” host on which the device is mounted is allowed access to a secure data area of the device automatically, without the user having to enter a password. Ways in which a host is designated as “trusted” include storing the host's ID in a trusted host list of the device, storing a representation of the host's ID that was encrypted using a trust key of the device in a cookie in the host, or storing a storage password of the device in a password list of the host. Alternatively, an untrusted host is allowed access to the secure data area if a user enters a correct user password.