Secure Boot Assembly for Data Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed computing networks are vulnerable to third-party attacks during boot operations, as they rely on remote connections for security verification, which can compromise firmware and data integrity.

Innovation Solution

A secure boot assembly with a security module connects to the data storage device's front end bus, allowing for offline verification of trustworthiness and authentication of security information, ensuring secure boot operations without network dependence.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the data storage device relies on remote network connections for security verification during boot operations, then network connectivity and remote management capabilities are improved, but security vulnerability to third-party attacks and firmware integrity compromise worsens

Engineering Contradiction:
Improveremote management capabilityVSAvoidfirmware integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary security verification by authenticating the security module against the boot module before the device connects to any network. This pre-authentication ensures firmware integrity is established in advance, creating a secure foundation that prevents third-party attacks during subsequent network operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a dedicated security module as an intermediary component that handles authentication and security verification. This separate module acts as a mediator between the boot module and network operations, isolating security-critical functions from network vulnerabilities while maintaining remote management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the data storage device performs complete boot operations with full data storage capabilities, then functionality and productivity are improved, but exposure to network attacks and security risks worsens

Engineering Contradiction:
Improvedata storage capabilityVSAvoidnetwork attack exposure
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the boot process into distinct phases: an initial boot sequence that provides limited functionality without network connectivity, and a subsequent phase that enables full data storage capabilities only after security verification is complete. This segmentation allows the device to achieve full productivity while minimizing exposure to network attacks during the vulnerable boot phase.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If the data storage device connects to network during boot operations, then remote host access and data accessibility are improved, but boot operation security and trustworthiness verification worsen

Engineering Contradiction:
Improveremote accessVSAvoidtrustworthiness verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs trustworthiness verification as a preliminary action before establishing any network connections during boot operations. The boot module authenticates the security module in advance, ensuring that remote access is only enabled after the device's integrity is confirmed, thereby maintaining both ease of operation and reliability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11645393B2Secure booting in a data storage device with front end bus
Publication Date: 2023.05.09 SEAGATE TECH LLC
  • US11645393B2 patent drawing
  • US11645393B2 patent drawing
  • US11645393B2 patent drawing

AI summary

A data storage device can employ a front end bus for boot operations. The physical connection of a secure boot assembly to the front end bus can provide efficient and reliable booting of the data storage device without a connection to a remote host or network. A secure boot assembly can provide a security module that connects to the boot module of the data storage device to authenticate a trustworthiness of the data storage device while the data storage device is disconnected from any remote host.