Recovery Key for Data Storage Device Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage devices with encryption technologies are cumbersome for unskilled users to set up and often store keys and passwords insecurely, leading to unused encryption and exposed confidential data.
Innovation Solution
A data storage device that uses a recovery key for unlocking, employing a cryptography engine and access controller to manage access through cryptographic methods, allowing decryption with a suitable key regardless of user or device role, and enabling registration of authorized devices without relying on access control lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional encryption with passwords and keys is used, then data security is improved, but user setup becomes cumbersome and complicated
Solution Approach 1:
The patent introduces a manager device as an intermediary that handles key management operations. The manager device stores encrypted authorization data and communicates with the data storage device, eliminating the need for users to directly manage complex cryptographic keys and passwords. This mediator approach maintains security while simplifying user interaction.
Solution Approach 2:
The system implements self-service through automated challenge-response authentication. When a recovery manager device needs to access encrypted data, the data storage device automatically generates challenges based on decrypted authorization data, and the manager device automatically provides responses without requiring manual user intervention in the cryptographic process.
2Adaptability or versatility
If access control lists are used for key management, then access control becomes systematic, but system complexity increases
Solution Approach 1:
The patent replaces traditional access control list mechanisms with a cryptographic challenge-response system. Instead of using structured access control data structures that require systematic management, the system uses cryptographic protocols where authorization is proven through mathematical challenges and responses, eliminating the need for complex access control list maintenance.
Solution Approach 2:
The system changes the fundamental parameter of access control from discrete permission lists to continuous cryptographic verification. Authorization is not determined by checking against predefined access control entries but by successfully responding to cryptographic challenges, fundamentally changing how access control is implemented and managed.
3Reliability
If recovery keys are stored securely, then data protection is improved, but key retrieval becomes difficult for unskilled users
Solution Approach 1:
The manager device serves as an intermediary that securely stores encrypted authorization data and retrieves it automatically when needed. Users don't need to manually retrieve or manage recovery keys; the manager device handles the secure storage and automatic retrieval through cryptographic protocols, maintaining data protection while simplifying user operations.
Solution Approach 2:
The system implements self-service for key retrieval through automated authentication protocols. When a recovery manager device connects to the data storage device, the system automatically performs challenge-response authentication and retrieves the necessary authorization data without requiring users to manually locate or enter recovery keys, making the process accessible to unskilled users.
Data Source
AI summary
Disclosed herein is a data storage device comprising a data path and an access controller. The access controller generates a recovery private key, generates encrypted authorization data based on the recovery private key, stores the encrypted authorization data, and sends the recovery private key to a manager device. When recovery is desired, access controller receives a recovery public key, calculated based on the recovery private key, from a recovery manager device, decrypts the encrypted authorization data based on the recovery public key, generates a challenge for the recovery manager device based on the decrypted authorization data, sends the challenge to the recovery manager device over the communication channel that is different from the data path, receives a response to the challenge from the recovery manager device over the communication channel, and based at least partly on the response, enables decryption of the encrypted user content data.


