Removable Key Management Device for SED Unlocking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Self-encrypting data storage devices (SEDs) require secure and efficient key management to unlock and manage encrypted data, especially when connected to different servers, as existing solutions lack a standardized method for remote key retrieval and management.

Innovation Solution

A removable key management device (KMD) with a secure nonvolatile storage area and a controller that loads a key management operating system to access hardware encryption circuits, transmit authentication certificates to a KMIP server, and receive encrypted keys to unlock SEDs, allowing secure and standardized key management across servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a removable key management device is used to enable flexible connection to different servers, then adaptability is improved, but security risks increase due to potential unauthorized access

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a key management device as an intermediary component that physically connects to the server's hardware encryption circuit. This intermediary enables flexible server connections while maintaining security through controlled access mechanisms, including authentication processes and audit logging that track all access attempts to encrypted data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary authentication and authorization actions before allowing access to encrypted data. The key management device establishes security credentials and access rights in advance, ensuring that only authenticated users can access the removable device, thus preventing unauthorized access while maintaining adaptability.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If remote key retrieval is implemented to enable key management outside the server, then ease of operation is improved, but security risks increase due to potential key compromise

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The key management device serves as a secure intermediary that enables remote key retrieval operations. It maintains the encryption key in a protected environment while allowing authorized operations to be performed remotely through the hardware encryption circuit interface, thus providing ease of operation without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments the key management functionality into separate components: the removable key management device that holds the encryption key and the server that performs encryption/decryption operations. This segmentation allows remote key retrieval and management operations while maintaining security by keeping the key isolated in a dedicated secure device.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If authentication certificates are transmitted to KMIP server for key retrieval, then key management functionality is improved, but device complexity increases due to additional communication protocols

Engineering Contradiction:
ImprovefunctionalityVSAvoidcomplexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The key management device implements universal communication capabilities that support multiple protocols including KMIP (Key Management Interoperability Protocol). This multi-functionality allows the device to communicate with different key management servers and perform various operations (key retrieval, authentication, authorization) through a unified interface, improving adaptability while managing complexity through standardized protocols.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10382201B1Removable circuit for unlocking self-encrypting data storage devices
Publication Date: 2019.08.13 SEAGATE TECH LLC
  • US10382201B1 patent drawing
  • US10382201B1 patent drawing
  • US10382201B1 patent drawing

AI summary

Security of data storage devices and servers can be improved by the system and methods described herein. In some embodiments, a key management device of a server can be a locally (or virtually) located data storage device such as a HDD or SDD. The key management device may be part of a server system and can have a secure area protected by a cryptographic module (e.g. hardware integrated circuit). The secure area can store a certificate needed to authenticate another data storage device coupled to the server. A second server may authenticate the certificate and provide the access key to the another data storage device.