Removable Storage Device Key Management Circuit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems face challenges in securely unlocking and managing self-encrypting data storage devices (SEDs) across servers, particularly in scenarios where encryption keys are remotely stored and need to be accessed for secure communication and data access.
Innovation Solution
A removable data storage device with a key management system that connects to a server, loads a key management protocol, and uses a hardware encryption circuit to access and transmit authentication certificates to unlock SEDs, enabling secure communication and access to encrypted data storage.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If encryption keys are remotely stored and transmitted to unlock SEDs, then secure data access across servers is enabled, but the risk of key interception and communication security vulnerabilities increases
Solution Approach 1:
The patent introduces a hardware encryption circuit as an intermediary component that never stores plaintext encryption keys. Instead, the circuit receives encrypted key material, performs decryption operations internally, and outputs decrypted keys only for immediate use in unlocking SEDs. This mediator approach ensures keys are never exposed in plaintext form during transmission or storage, eliminating the vulnerability to key interception while maintaining cross-server data access capability.
2Ease of operation
If a removable data storage device with key management system is used, then key management flexibility and portability are improved, but the complexity of the system increases
Solution Approach 1:
The patent combines multiple functions into a single removable data storage device: (1) key management system for generating and managing encryption keys, (2) secure storage for storing encrypted key material and authentication certificates, and (3) hardware encryption circuit for decryption operations. This consolidation eliminates the need for separate key management hardware, software modules, and storage systems, reducing overall system complexity while maintaining operational flexibility and portability across different servers.
3Reliability
If authentication certificates are stored in secure nonvolatile data storage area, then authentication security is enhanced, but access control complexity increases
Solution Approach 1:
The patent implements self-service authentication where the hardware encryption circuit automatically verifies authentication certificates stored in the secure nonvolatile data storage area without requiring external authentication mechanisms. The circuit uses embedded logic to validate certificates and grant access to decryption operations, eliminating the need for complex external authentication systems while maintaining high security standards. This self-verification approach simplifies access control while enhancing authentication reliability.
Data Source
AI summary
Security of data storage devices and servers can be improved by the system and methods described herein. In some embodiments, a key management server may be locally or externally located. An encryption key may be used for locking a portion or the entirety of a storage device. The key management server may communicate with data storage devices regarding encryption keys using secure protocols. For example, the key management server may generate a communication key that may be used to securely encrypt messages between the server and a data storage device.


