Self-Encrypting Drive Key Injection via KMIP

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional self-encrypting drives (SEDs) face limitations in security management interfaces, making it difficult for datacenters to effectively utilize them in storage appliances for encrypted virtual storage, particularly due to password-based unlocking mechanisms that are not compatible with electronic distribution and entry, and lack of fine-grain encryption flexibility.

Innovation Solution

The technology introduces fine-grain encryption and secure key injection on SEDs by directly injecting media encryption keys (MEKs) protected using the Key Management Interoperability Protocol (KMIP), enabling software-based mapping of input/output operations and hardware-based storage of unique identifiers to verify key correctness, thus addressing FIPS certification and encryption granularity challenges.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If password-based unlocking mechanism is used in conventional SEDs, then access control is provided, but compatibility with electronic distribution and entry is lost

Engineering Contradiction:
Improveaccess controlVSAvoidcompatibility with electronic distribution and entry
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent changes the authentication parameter from password-based to certificate-based authentication. The SED controller now uses cryptographic certificates and key pairs instead of passwords, enabling compatibility with electronic distribution and entry while maintaining secure access control. This parameter change allows the system to work with automated key management systems.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the manual password-based authentication mechanism with an automated cryptographic system. Instead of relying on human-operated passwords, the system uses automated certificate validation, public key infrastructure, and cryptographic protocols to authenticate access requests, enabling electronic distribution and entry compatibility.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If conventional SED encryption is used, then data protection is provided, but fine-grain encryption flexibility is lost

Engineering Contradiction:
Improvedata protectionVSAvoidencryption granularity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the encryption key management into multiple independent components: client-specific key pairs, SED controller-specific certificates, and per-volume encryption keys. This segmentation allows different encryption keys to be applied to different logical volumes or partitions, enabling fine-grain encryption control while maintaining strong data protection through cryptographic security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic key management where encryption keys can be dynamically generated, assigned, revoked, and updated based on client needs and security policies. The system can dynamically provision different encryption keys for different clients or volumes, providing fine-grain control while maintaining continuous data protection through automated key lifecycle management.

Inventive Principle:
Principle #15Dynamics

3Reliability

If secure key injection is implemented, then key management security is improved, but system complexity increases

Engineering Contradiction:
Improvekey management securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service key management where the SED controller autonomously generates cryptographic key pairs, manages certificate validation, and handles key injection without requiring manual intervention. The system automatically provisions encryption keys, validates client certificates, and manages key lifecycles, improving security while reducing operational complexity through automation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a key management service as an intermediary between clients and the SED controller. This service handles complex cryptographic operations, certificate validation, and key distribution, simplifying the overall system by centralizing security management functions and reducing the complexity burden on individual components.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If hardware-based unique identifier storage is used, then key verification accuracy is improved, but manufacturing complexity increases

Engineering Contradiction:
Improvekey verification accuracyVSAvoidmanufacturing complexity
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The patent merges the unique identifier storage with the SED controller's existing hardware security features. Rather than adding separate hardware components, the system integrates cryptographic identity verification into the controller's secure element or trusted platform module, improving key verification accuracy while minimizing manufacturing complexity by utilizing existing hardware security infrastructure.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11599479B2Technology for fine-grain encryption and secure key injection on self-encrypting drives
Publication Date: 2023.03.07 SK HYNIX NAND PRODUCT SOLUTIONS CORP
  • US11599479B2 patent drawing
  • US11599479B2 patent drawing
  • US11599479B2 patent drawing

AI summary

A self-encrypting drive (SED) comprises an SED controller and a nonvolatile storage medium (NVSM) responsive to the SED controller. The SED controller enables the SED to perform operations comprising: (a) receiving an encrypted media encryption key (eMEK) for a client; (b) decrypting the eMEK into an unencrypted media encryption key (MEK); (c) receiving a write request from the client, wherein the write request includes data to be stored and a key tag value associated with the MEK; (d) using the key tag value to select the MEK for the write request; (e) using the MEK for the write request to encrypt the data from the client; and (f) storing the encrypted data in a region of the NVSM allocated to the client. Other embodiments are described and claimed.