Radiation-Tolerant Storage Controller for Secure Aerospace Data Arrays
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial data storage devices are unreliable in high radiation and temperature environments, such as Low-Earth-Orbit spacecraft, due to lack of radiation hardening and security vulnerabilities, making them susceptible to cyber threats and data integrity issues.
Innovation Solution
A data storage system with radiation-hardened components and a security-enhanced storage controller (SESSD) that includes a FPGA-based root-of-trust and security policy engine, implementing secure firmware loading, data sanitization, encryption, and authentication to ensure data integrity and confidentiality.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If commercial data storage devices are used in aerospace environments, then cost and ease of manufacture are improved, but reliability and resistance to radiation are worsened
Solution Approach 1:
The storage system is divided into multiple independent storage drives organized in an array, where each drive operates independently. This segmentation allows the use of commercial off-the-shelf drives while maintaining system reliability through redundancy and distributed data storage across multiple units.
Solution Approach 2:
A radiation-tolerant storage controller is introduced as an intermediary between the bus host and the commercial storage drives. This controller provides radiation resistance and security functions, protecting the vulnerable commercial drives from radiation effects while allowing them to be used in the aerospace environment.
2Device complexity
If commercial data storage devices are used, then device complexity is reduced, but security vulnerability and susceptibility to cyber threats increase
Solution Approach 1:
The radiation-tolerant storage controller acts as a security intermediary that implements security logic and root-of-trust verification. It authenticates firmware, encrypts data, and manages security policies, protecting commercial drives from cyber threats while maintaining their simplicity.
Solution Approach 2:
Security measures are implemented in advance through the controller, including firmware authentication before execution, encryption keys generated beforehand, and security policies configured prior to operation. This preliminary anti-action prevents security breaches before they can affect the storage system.
3Reliability
If radiation-tolerant components are implemented, then reliability in high radiation environments is improved, but device complexity and manufacturing difficulty increase
Solution Approach 1:
The system separates radiation-tolerant functions (controller) from non-radiation-hardened components (storage drives). This segmentation allows only the critical control functions to be radiation-hardened, reducing overall complexity compared to hardening entire drive assemblies.
Solution Approach 2:
The radiation-tolerant storage controller performs multiple functions including data management, security authentication, encryption, and radiation tolerance. This multi-functionality consolidates complexity into a single component rather than distributing it across multiple specialized components.
4Loss of information
If security logic and authentication mechanisms are added, then data confidentiality and authenticity are improved, but processing time and operational complexity increase
Solution Approach 1:
Security credentials, encryption keys, and authentication mechanisms are established during system initialization and firmware loading before normal operation begins. This preliminary action ensures security is already in place during data operations, avoiding time-consuming security checks during critical data access operations.
Data Source
AI summary
A system for use in an aerospace environment includes an array of storage drives each comprising a non-radiation-hardened drive controller, a non-radiation-hardened, non-volatile, storage medium, and a non-radiation-hardened volatile memory. The system includes a radiation-tolerant storage controller coupled to the array. The storage controller provides failure-resistant data redundancy among the storage drives of the array. The system includes a bus host that accesses the array via the storage controller. The storage controller implements security logic and a root-of-trust that provides to the bus host verification of authenticity of the radiation tolerant storage controller and the storage drives.


