Automated Secure Data Migration Between Removable Storage Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current storage device upgrade technologies face challenges in seamlessly migrating boot partitions and replay protected memory blocks during storage device replacements, leading to potential operational failures without proper system data transfer.
Innovation Solution
An automated data migration management system that utilizes a trusted execution environment to transfer storage context information, including factory data, security data, and boot firmware, between removable storage devices, ensuring secure and efficient migration by creating necessary partitions and provisioning replay protected memory blocks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If storage devices are made removable to enable upgrades, then ease of operation and adaptability improve, but reliability deteriorates due to potential operational failures during migration
Solution Approach 1:
The system performs preliminary actions by detecting migration requests before the actual storage device replacement occurs. The boot subsystem proactively initiates the transfer of storage context information (including boot firmware, security data, and factory data) from the first removable storage device to a secure memory region, ensuring that critical system data is preserved before the old device is removed and the new device is installed.
Solution Approach 2:
The patent introduces a secure memory region as an intermediary between the removable storage devices and the system. This intermediary temporarily holds storage context information during the migration process, allowing seamless transfer from the first removable storage device to the second removable storage device without direct exposure or potential loss of critical data.
2Reliability
If automated data migration is implemented to ensure reliability, then operational continuity improves, but device complexity increases due to additional controllers and migration management
Solution Approach 1:
The boot subsystem is designed with multi-functionality, serving both as a system initialization component and as a data migration management apparatus. By integrating the migration detection and execution capabilities within the existing boot subsystem, the patent avoids adding separate dedicated migration controllers, thereby reducing overall system complexity while maintaining automated migration functionality.
Solution Approach 2:
The patent combines multiple functions into unified components: the boot subsystem simultaneously performs system initialization and migration request handling; the secure memory region serves as both a secure storage area and a temporary transfer buffer; the trusted execution environment provides both security enforcement and migration orchestration. This merging reduces the number of separate controllers and simplifies the overall architecture.
3Reliability
If secure memory region and trusted execution environment are used for data transfer, then security and reliability improve, but device complexity and resource requirements increase
Solution Approach 1:
The trusted execution environment operates autonomously to enforce security policies during the migration process. It automatically verifies the authenticity of storage context information, manages cryptographic operations for secure data transfer, and controls access to the secure memory region without requiring external security management hardware, thereby providing high security while minimizing additional complexity.
Solution Approach 2:
The system performs preliminary security setup by establishing the secure memory region and configuring the trusted execution environment before the migration process begins. This preliminary configuration ensures that security mechanisms are in place and verified beforehand, allowing the actual data transfer to proceed with minimal additional overhead and complexity during the migration execution phase.
Data Source
AI summary
Systems, apparatuses and methods may include technology that detects a migration request and conducts a first transfer, via a trusted execution environment (TEE), of storage context information from a first removable storage device to a secure memory region of a system in response to the data migration request. Additionally, the technology may conduct a second transfer, via the TEE, of the storage context information from the secure memory region to a second removable storage device, wherein the storage context information includes factory data, security data and boot firmware.


