Removable Storage Device Key Management Circuit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in securely unlocking and managing self-encrypting data storage devices (SEDs) across servers, particularly in scenarios where encryption keys are remotely stored and need to be accessed for secure communication and data access.

Innovation Solution

A removable data storage device with a key management system that connects to a server, loads a key management protocol, and uses a hardware encryption circuit to access and transmit authentication certificates to unlock SEDs, enabling secure communication and access to encrypted data storage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If encryption keys are remotely stored and transmitted to unlock SEDs, then secure data access across servers is enabled, but the risk of key interception and communication security vulnerabilities increases

Engineering Contradiction:
Improvesecure data access across serversVSAvoidkey interception risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a hardware encryption circuit as an intermediary component that never stores plaintext encryption keys. Instead, the circuit receives encrypted key material, performs decryption operations internally, and outputs decrypted keys only for immediate use in unlocking SEDs. This mediator approach ensures keys are never exposed in plaintext form during transmission or storage, eliminating the vulnerability to key interception while maintaining cross-server data access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If a removable data storage device with key management system is used, then key management flexibility and portability are improved, but the complexity of the system increases

Engineering Contradiction:
Improvekey management flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent combines multiple functions into a single removable data storage device: (1) key management system for generating and managing encryption keys, (2) secure storage for storing encrypted key material and authentication certificates, and (3) hardware encryption circuit for decryption operations. This consolidation eliminates the need for separate key management hardware, software modules, and storage systems, reducing overall system complexity while maintaining operational flexibility and portability across different servers.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If authentication certificates are stored in secure nonvolatile data storage area, then authentication security is enhanced, but access control complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service authentication where the hardware encryption circuit automatically verifies authentication certificates stored in the secure nonvolatile data storage area without requiring external authentication mechanisms. The circuit uses embedded logic to validate certificates and grant access to decryption operations, eliminating the need for complex external authentication systems while maintaining high security standards. This self-verification approach simplifies access control while enhancing authentication reliability.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10855451B1Removable circuit for unlocking self-encrypting data storage devices
Publication Date: 2020.12.01 SEAGATE TECH LLC
  • US10855451B1 patent drawing
  • US10855451B1 patent drawing
  • US10855451B1 patent drawing

AI summary

Security of data storage devices and servers can be improved by the system and methods described herein. In some embodiments, a key management server may be locally or externally located. An encryption key may be used for locking a portion or the entirety of a storage device. The key management server may communicate with data storage devices regarding encryption keys using secure protocols. For example, the key management server may generate a communication key that may be used to securely encrypt messages between the server and a data storage device.