Removable Access Control Device for Storage Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing storage solutions fail to adequately protect data on computer-readable media when devices are physically accessed by malicious or adversarial parties, and current security measures are costly, time-consuming, and inefficient, especially in scenarios like server environments where storage devices are frequently moved and accessed.
Innovation Solution
A storage system with a physically and communicationally separable access control device that can provision cryptographic information and access control lists to control access to encrypted data, allowing selective encryption and decryption, and enabling secure communication tunnels to authorize data access, while also allowing for secure erasure of data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical destruction of computer-readable storage media is performed to protect data, then data security is improved, but cost and time consumption increase
Solution Approach 1:
The patent implements secure erasure policies that overwrite data multiple times before physical destruction is needed. This preliminary action ensures data cannot be recovered even if the device is later compromised, eliminating the need for immediate physical destruction and reducing time consumption while maintaining security
Solution Approach 2:
The patent separates the cryptographic information storage function from the main storage device by using a removable access control device. This extraction allows the main storage device to be destroyed or discarded without compromising data security, as the cryptographic keys remain protected in the separate access control device
2Reliability
If access control is provisioned on storage devices to control data access, then data security is improved, but device complexity and cost increase
Solution Approach 1:
The patent divides the access control functionality into a separate, removable access control device that contains cryptographic information. This segmentation isolates the complex security functions from the main storage device, simplifying the main device while maintaining strong security through the dedicated access control module
Solution Approach 2:
The patent introduces an access control device as an intermediary between the storage device and potential accessors. This intermediary handles all authentication and authorization operations, simplifying the storage device's role to merely storing data while the complex access control logic resides in the intermediary device
3Reliability
If full volume encryption is implemented on storage devices, then data security against physical access is improved, but processing performance decreases
Solution Approach 1:
The patent replaces software-based encryption processing with hardware-based cryptographic systems. This substitution provides dedicated cryptographic processing that maintains strong security while improving performance by offloading encryption/decryption operations from the main CPU to specialized hardware on the storage device
Data Source
Figure 1
Figure 2
Figure 3
AI summary
An access control device can be communicationally coupled to a storage device and can control access thereto. The access control device can comprise information, such as identities of authorized entities, to enable the access control device to independently determine whether to provide access to an associated storage device. Alternatively, the access control device can comprise information to establish a secure connection to an authorization computing device and the access control device can implement the decisions of the authorization computing device. The access control device can control access by instructing a storage device to execute specific firmware instructions to prevent meaningful responses to data storage related requests. The access control device can also comprise storage-related cryptographic information utilized by the storage device to encrypt and decrypt data. In such a case, the access control device can control access by not releasing the storage-related cryptographic information to the storage device.