Self-Encrypting Drive Key Injection via KMIP
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional self-encrypting drives (SEDs) face limitations in security management interfaces, making it difficult for datacenters to effectively utilize them in storage appliances for encrypted virtual storage, particularly due to password-based unlocking mechanisms that are not compatible with electronic distribution and entry, and lack of fine-grain encryption flexibility.
Innovation Solution
The technology introduces fine-grain encryption and secure key injection on SEDs by directly injecting media encryption keys (MEKs) protected using the Key Management Interoperability Protocol (KMIP), enabling software-based mapping of input/output operations and hardware-based storage of unique identifiers to verify key correctness, thus addressing FIPS certification and encryption granularity challenges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If password-based unlocking mechanism is used in conventional SEDs, then access control is provided, but compatibility with electronic distribution and entry is lost
Solution Approach 1:
The patent changes the authentication parameter from password-based to certificate-based authentication. The SED controller now uses cryptographic certificates and key pairs instead of passwords, enabling compatibility with electronic distribution and entry while maintaining secure access control. This parameter change allows the system to work with automated key management systems.
Solution Approach 2:
The patent replaces the manual password-based authentication mechanism with an automated cryptographic system. Instead of relying on human-operated passwords, the system uses automated certificate validation, public key infrastructure, and cryptographic protocols to authenticate access requests, enabling electronic distribution and entry compatibility.
2Reliability
If conventional SED encryption is used, then data protection is provided, but fine-grain encryption flexibility is lost
Solution Approach 1:
The patent segments the encryption key management into multiple independent components: client-specific key pairs, SED controller-specific certificates, and per-volume encryption keys. This segmentation allows different encryption keys to be applied to different logical volumes or partitions, enabling fine-grain encryption control while maintaining strong data protection through cryptographic security.
Solution Approach 2:
The patent introduces dynamic key management where encryption keys can be dynamically generated, assigned, revoked, and updated based on client needs and security policies. The system can dynamically provision different encryption keys for different clients or volumes, providing fine-grain control while maintaining continuous data protection through automated key lifecycle management.
3Reliability
If secure key injection is implemented, then key management security is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service key management where the SED controller autonomously generates cryptographic key pairs, manages certificate validation, and handles key injection without requiring manual intervention. The system automatically provisions encryption keys, validates client certificates, and manages key lifecycles, improving security while reducing operational complexity through automation.
Solution Approach 2:
The patent introduces a key management service as an intermediary between clients and the SED controller. This service handles complex cryptographic operations, certificate validation, and key distribution, simplifying the overall system by centralizing security management functions and reducing the complexity burden on individual components.
4Measurement precision
If hardware-based unique identifier storage is used, then key verification accuracy is improved, but manufacturing complexity increases
Solution Approach 1:
The patent merges the unique identifier storage with the SED controller's existing hardware security features. Rather than adding separate hardware components, the system integrates cryptographic identity verification into the controller's secure element or trusted platform module, improving key verification accuracy while minimizing manufacturing complexity by utilizing existing hardware security infrastructure.
Data Source
AI summary
A self-encrypting drive (SED) comprises an SED controller and a nonvolatile storage medium (NVSM) responsive to the SED controller. The SED controller enables the SED to perform operations comprising: (a) receiving an encrypted media encryption key (eMEK) for a client; (b) decrypting the eMEK into an unencrypted media encryption key (MEK); (c) receiving a write request from the client, wherein the write request includes data to be stored and a key tag value associated with the MEK; (d) using the key tag value to select the MEK for the write request; (e) using the MEK for the write request to encrypt the data from the client; and (f) storing the encrypted data in a region of the NVSM allocated to the client. Other embodiments are described and claimed.


