Secure Access Control Module for Self-Encrypting Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing self-encrypting storage devices lack user-configurable security features, posing a risk of unauthorized access control enablement by malicious attackers, which compromises the legitimate user's ownership.

Innovation Solution

Incorporating a secure access control module with a non-volatile memory that verifies physical presence through a Physical Security Identifier (PSID) and allows users to enable or disable access controls, using encryption standards like AES, to ensure secure activation and provisioning of access controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If access controls are made user-configurable, then ease of operation is improved, but security is worsened due to risk of unauthorized enablement

Engineering Contradiction:
Improveuser-configurable security featuresVSAvoidsecurity integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary verification of physical presence using PSID before allowing access control enablement. This preliminary action prevents unauthorized configuration changes by ensuring only the legitimate user (in possession of the physical device) can modify security settings, thus resolving the contradiction between user-configurability and security integrity

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If access controls are enabled remotely without physical verification, then ease of operation is improved, but security is worsened due to potential unauthorized access control enablement

Engineering Contradiction:
Improveremote configuration capabilityVSAvoidunauthorized access control enablement
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by requiring physical presence verification (PSID) before allowing access control enablement. This counter-measure prevents the harmful effect of unauthorized remote configuration while still allowing legitimate users to configure security features remotely after verification, thus resolving the contradiction between remote configuration capability and prevention of unauthorized enablement

Inventive Principle:
Principle #9Preliminary anti-action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

This solution provides secure control of access control enablement and activation on self-encrypting storage devices, preventing unauthorized access and ensuring the integrity of the storage device remains with the legitimate user.

Implementation Method 1

an encryption module to allow encryption of at least a portion of the NVM when the access controls have been activated

Methodology Applied
Scientific EffectEncryption:

Data Source

PatentUS9626531B2Secure control of self-encrypting storage devices
Publication Date: 2017.04.18 SK HYNIX NAND PRODUCT SOLUTIONS CORP
  • US9626531B2 patent drawing
  • US9626531B2 patent drawing
  • US9626531B2 patent drawing

AI summary

Generally, this disclosure provides systems, devices, methods and computer readable media for secure control of access control enablement and activation on self-encrypting storage devices. In some embodiments, the device may include a non-volatile memory (NVM) and a secure access control module. The secure access control module may include a command processor module configured to receive a request to enable access controls of the NVM from a user, and to enable the access controls. The secure access control module may also include a verification module configured to verify a physical presence of the user. The secure access control module may further include an encryption module to encrypt at least a portion of the NVM in response to an indication of success from the verification module.