SCSI Storage Device Secure Authentication Memory Integration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable devices face challenges in integrating secure storage due to limited space, power, and component budgets, as existing SCSI storage devices do not provide secure, authenticated, and separate storage areas for sensitive data like cryptographic keys without additional components.

Innovation Solution

A method is implemented within a SCSI storage device to create an authenticated communication pathway using a trusted execution environment and security memory, enabling secure storage by transmitting authentication keys and data buffers to verify authenticity, thus eliminating the need for additional secure storage components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a discrete secure storage component is added to provide secure storage, then security is improved, but device complexity and cost increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the secure storage functionality with the existing SCSI storage device by creating a secure authenticated separate storage area within the same device. The SCSI storage device is divided into a first storage area for user data and a second storage area for secure data, eliminating the need for a separate discrete secure storage component while maintaining security requirements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The SCSI storage device is designed to perform multiple functions: it serves as both a regular storage device for user data and a secure storage device for sensitive information. The device includes authentication mechanisms and encrypted file systems that enable it to provide both standard storage and secure storage capabilities within a single device.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a discrete secure storage component is added to provide secure storage, then security is improved, but cost increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent merges secure storage functionality into the existing SCSI storage device, eliminating the need to manufacture and assemble separate secure storage components. This integration reduces manufacturing costs by utilizing the existing device structure while adding security features through software and authentication protocols.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If authentication mechanisms are implemented within SCSI storage device, then secure storage is enabled, but device complexity increases

Engineering Contradiction:
Improvesecure storageVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an authentication key as an intermediary element that enables secure communication between the trusted execution environment and the security memory within the SCSI storage device. This authentication mechanism allows the device to verify the authenticity of data buffers and establish secure storage capabilities without requiring complex hardware security modules.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If secure authenticated separate storage area is created within SCSI device, then security is improved, but existing SCSI device functionality is modified

Engineering Contradiction:
ImprovesecurityVSAvoidcompatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the SCSI storage device into distinct storage areas: a first storage area for general user data and a second storage area for secure authenticated storage. This segmentation allows the device to maintain its existing functionality for standard storage operations while providing enhanced security capabilities in the separate authenticated area without compromising overall compatibility.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9071581B2Secure storage with SCSI storage devices
Publication Date: 2015.06.30 NVIDIA CORP
  • US9071581B2 patent drawing
  • US9071581B2 patent drawing
  • US9071581B2 patent drawing

AI summary

A security command protocol provides secure authenticated access to an auxiliary security memory within a SCSI storage device. The auxiliary security memory acts as an authenticated separate secure storage area that stores sensitive data separately from the user data area of the SCSI storage device. The security command protocol is used to access the auxiliary security memory. The security command protocol allows a trusted execution environment to transport sensitive data to and from storage in the auxiliary security memory. The regular execution environment does not have access to the security command protocol or the auxiliary security memory. The security command protocol and auxiliary security memory eliminate the need for additional secure storage components in devices that provide the security features of firmware TPM.