Automated Secure Data Migration Between Removable Storage Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current storage device upgrade technologies face challenges in seamlessly migrating boot partitions and replay protected memory blocks during storage device replacements, leading to potential operational failures without proper system data transfer.

Innovation Solution

An automated data migration management system that utilizes a trusted execution environment to transfer storage context information, including factory data, security data, and boot firmware, between removable storage devices, ensuring secure and efficient migration by creating necessary partitions and provisioning replay protected memory blocks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If storage devices are made removable to enable upgrades, then ease of operation and adaptability improve, but reliability deteriorates due to potential operational failures during migration

Engineering Contradiction:
Improvestorage device upgrade capabilityVSAvoidoperational continuity during migration
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by detecting migration requests before the actual storage device replacement occurs. The boot subsystem proactively initiates the transfer of storage context information (including boot firmware, security data, and factory data) from the first removable storage device to a secure memory region, ensuring that critical system data is preserved before the old device is removed and the new device is installed.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure memory region as an intermediary between the removable storage devices and the system. This intermediary temporarily holds storage context information during the migration process, allowing seamless transfer from the first removable storage device to the second removable storage device without direct exposure or potential loss of critical data.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If automated data migration is implemented to ensure reliability, then operational continuity improves, but device complexity increases due to additional controllers and migration management

Engineering Contradiction:
Improveoperational continuity during migrationVSAvoidcontroller architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The boot subsystem is designed with multi-functionality, serving both as a system initialization component and as a data migration management apparatus. By integrating the migration detection and execution capabilities within the existing boot subsystem, the patent avoids adding separate dedicated migration controllers, thereby reducing overall system complexity while maintaining automated migration functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines multiple functions into unified components: the boot subsystem simultaneously performs system initialization and migration request handling; the secure memory region serves as both a secure storage area and a temporary transfer buffer; the trusted execution environment provides both security enforcement and migration orchestration. This merging reduces the number of separate controllers and simplifies the overall architecture.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If secure memory region and trusted execution environment are used for data transfer, then security and reliability improve, but device complexity and resource requirements increase

Engineering Contradiction:
Improvedata transfer securityVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted execution environment operates autonomously to enforce security policies during the migration process. It automatically verifies the authenticity of storage context information, manages cryptographic operations for secure data transfer, and controls access to the secure memory region without requiring external security management hardware, thereby providing high security while minimizing additional complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary security setup by establishing the secure memory region and configuring the trusted execution environment before the migration process begins. This preliminary configuration ensures that security mechanisms are in place and verified beforehand, allowing the actual data transfer to proceed with minimal additional overhead and complexity during the migration execution phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10180800B2Automated secure data and firmware migration between removable storage devices that supports boot partitions and replay protected memory blocks
Publication Date: 2019.01.15 INTEL CORP
  • US10180800B2 patent drawing
  • US10180800B2 patent drawing
  • US10180800B2 patent drawing

AI summary

Systems, apparatuses and methods may include technology that detects a migration request and conducts a first transfer, via a trusted execution environment (TEE), of storage context information from a first removable storage device to a secure memory region of a system in response to the data migration request. Additionally, the technology may conduct a second transfer, via the TEE, of the storage context information from the secure memory region to a second removable storage device, wherein the storage context information includes factory data, security data and boot firmware.