Self-Encrypting Drive Authentication via External Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Self-encrypting drives (SEDs) according to the TCG standard have a low security level due to the ease with which a third party can access and execute the revert function by referencing the printed physical presence security identifier (PSID), compromising the initialization process.

Innovation Solution

An information processing system and method that includes a host and an authentication server separate from the memory system, where user authentication and memory authentication are performed through a user interface, command generator, and authentication processors, ensuring that only authorized users can initiate the initialization of the memory system by transmitting and verifying user and memory identification information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the PSID is printed on the SED for easy access, then the ease of operation is improved, but the security is worsened because third parties can easily refer to and execute the revert function

Engineering Contradiction:
Improveease of accessing PSIDVSAvoidsecurity of revert function
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication server as an intermediary between the host and memory system. This server verifies user credentials and authorization before allowing execution of the revert function, thereby maintaining ease of operation while improving security by preventing unauthorized access from third parties who may have obtained the PSID

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240427859A1Information processing system and information processing method
Publication Date: 2024.12.26 KIOXIA CORP
  • US20240427859A1 patent drawing
  • US20240427859A1 patent drawing
  • US20240427859A1 patent drawing

AI summary

An information processing system includes a memory system including a memory configured to store data; a host attachable to the memory system; and an authentication server. The host includes a user interface configured to transmit an initialization command to a command generator when an input is received from a user, generate user identification information for identifying the user, and transmit the generated user identification information to a first user authenticator. The command generator can transmit a first command, causing the memory system to start the initialization of the memory when the initialization command is received.