Removable Key Management Device for SED Unlocking
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Self-encrypting data storage devices (SEDs) require secure and efficient key management to unlock and manage encrypted data, especially when connected to different servers, as existing solutions lack a standardized method for remote key retrieval and management.
Innovation Solution
A removable key management device (KMD) with a secure nonvolatile storage area and a controller that loads a key management operating system to access hardware encryption circuits, transmit authentication certificates to a KMIP server, and receive encrypted keys to unlock SEDs, allowing secure and standardized key management across servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a removable key management device is used to enable flexible connection to different servers, then adaptability is improved, but security risks increase due to potential unauthorized access
Solution Approach 1:
The patent introduces a key management device as an intermediary component that physically connects to the server's hardware encryption circuit. This intermediary enables flexible server connections while maintaining security through controlled access mechanisms, including authentication processes and audit logging that track all access attempts to encrypted data.
Solution Approach 2:
The system performs preliminary authentication and authorization actions before allowing access to encrypted data. The key management device establishes security credentials and access rights in advance, ensuring that only authenticated users can access the removable device, thus preventing unauthorized access while maintaining adaptability.
2Ease of operation
If remote key retrieval is implemented to enable key management outside the server, then ease of operation is improved, but security risks increase due to potential key compromise
Solution Approach 1:
The key management device serves as a secure intermediary that enables remote key retrieval operations. It maintains the encryption key in a protected environment while allowing authorized operations to be performed remotely through the hardware encryption circuit interface, thus providing ease of operation without compromising security.
Solution Approach 2:
The system segments the key management functionality into separate components: the removable key management device that holds the encryption key and the server that performs encryption/decryption operations. This segmentation allows remote key retrieval and management operations while maintaining security by keeping the key isolated in a dedicated secure device.
3Adaptability or versatility
If authentication certificates are transmitted to KMIP server for key retrieval, then key management functionality is improved, but device complexity increases due to additional communication protocols
Solution Approach 1:
The key management device implements universal communication capabilities that support multiple protocols including KMIP (Key Management Interoperability Protocol). This multi-functionality allows the device to communicate with different key management servers and perform various operations (key retrieval, authentication, authorization) through a unified interface, improving adaptability while managing complexity through standardized protocols.
Data Source
AI summary
Security of data storage devices and servers can be improved by the system and methods described herein. In some embodiments, a key management device of a server can be a locally (or virtually) located data storage device such as a HDD or SDD. The key management device may be part of a server system and can have a secure area protected by a cryptographic module (e.g. hardware integrated circuit). The secure area can store a certificate needed to authenticate another data storage device coupled to the server. A second server may authenticate the certificate and provide the access key to the another data storage device.


