Removable Access Control Device for Storage Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage solutions fail to adequately protect data on computer-readable media when devices are physically accessed by malicious or adversarial parties, and current security measures are costly, time-consuming, and inefficient, especially in scenarios like server environments where storage devices are frequently moved and accessed.

Innovation Solution

A storage system with a physically and communicationally separable access control device that can provision cryptographic information and access control lists to control access to encrypted data, allowing selective encryption and decryption, and enabling secure communication tunnels to authorize data access, while also allowing for secure erasure of data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical destruction of computer-readable storage media is performed to protect data, then data security is improved, but cost and time consumption increase

Engineering Contradiction:
Improvedata securityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements secure erasure policies that overwrite data multiple times before physical destruction is needed. This preliminary action ensures data cannot be recovered even if the device is later compromised, eliminating the need for immediate physical destruction and reducing time consumption while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent separates the cryptographic information storage function from the main storage device by using a removable access control device. This extraction allows the main storage device to be destroyed or discarded without compromising data security, as the cryptographic keys remain protected in the separate access control device

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If access control is provisioned on storage devices to control data access, then data security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the access control functionality into a separate, removable access control device that contains cryptographic information. This segmentation isolates the complex security functions from the main storage device, simplifying the main device while maintaining strong security through the dedicated access control module

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an access control device as an intermediary between the storage device and potential accessors. This intermediary handles all authentication and authorization operations, simplifying the storage device's role to merely storing data while the complex access control logic resides in the intermediary device

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If full volume encryption is implemented on storage devices, then data security against physical access is improved, but processing performance decreases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-based encryption processing with hardware-based cryptographic systems. This substitution provides dedicated cryptographic processing that maintains strong security while improving performance by offloading encryption/decryption operations from the main CPU to specialized hardware on the storage device

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP2443584B1Remote access control of storage devices
Publication Date: 2019.08.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2443584B1 patent drawingFigure 1
  • EP2443584B1 patent drawingFigure 2
  • EP2443584B1 patent drawingFigure 3

AI summary

An access control device can be communicationally coupled to a storage device and can control access thereto. The access control device can comprise information, such as identities of authorized entities, to enable the access control device to independently determine whether to provide access to an associated storage device. Alternatively, the access control device can comprise information to establish a secure connection to an authorization computing device and the access control device can implement the decisions of the authorization computing device. The access control device can control access by instructing a storage device to execute specific firmware instructions to prevent meaningful responses to data storage related requests. The access control device can also comprise storage-related cryptographic information utilized by the storage device to encrypt and decrypt data. In such a case, the access control device can control access by not releasing the storage-related cryptographic information to the storage device.