Secure Access Control Module for Self-Encrypting Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing self-encrypting storage devices lack user-configurable security features, posing a risk of unauthorized access control enablement by malicious attackers, which compromises the legitimate user's ownership.
Innovation Solution
Incorporating a secure access control module with a non-volatile memory that verifies physical presence through a Physical Security Identifier (PSID) and allows users to enable or disable access controls, using encryption standards like AES, to ensure secure activation and provisioning of access controls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If access controls are made user-configurable, then ease of operation is improved, but security is worsened due to risk of unauthorized enablement
Solution Approach 1:
The system performs preliminary verification of physical presence using PSID before allowing access control enablement. This preliminary action prevents unauthorized configuration changes by ensuring only the legitimate user (in possession of the physical device) can modify security settings, thus resolving the contradiction between user-configurability and security integrity
2Ease of operation
If access controls are enabled remotely without physical verification, then ease of operation is improved, but security is worsened due to potential unauthorized access control enablement
Solution Approach 1:
The system applies preliminary anti-action by requiring physical presence verification (PSID) before allowing access control enablement. This counter-measure prevents the harmful effect of unauthorized remote configuration while still allowing legitimate users to configure security features remotely after verification, thus resolving the contradiction between remote configuration capability and prevention of unauthorized enablement
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This solution provides secure control of access control enablement and activation on self-encrypting storage devices, preventing unauthorized access and ensuring the integrity of the storage device remains with the legitimate user.
Implementation Method 1
an encryption module to allow encryption of at least a portion of the NVM when the access controls have been activated
Data Source
AI summary
Generally, this disclosure provides systems, devices, methods and computer readable media for secure control of access control enablement and activation on self-encrypting storage devices. In some embodiments, the device may include a non-volatile memory (NVM) and a secure access control module. The secure access control module may include a command processor module configured to receive a request to enable access controls of the NVM from a user, and to enable the access controls. The secure access control module may also include a verification module configured to verify a physical presence of the user. The secure access control module may further include an encryption module to encrypt at least a portion of the NVM in response to an indication of success from the verification module.


