Self-Encrypting Drive Reversion Using Stored Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Reinitializing self-encrypting drives in a storage array to their manufacturing state is inefficient, especially when many drives are involved, as the process requires physical access to unique physical system IDs, which can be impractical and time-consuming, especially in scenarios where the storage array is faulted or in a development environment.

Innovation Solution

A computer-implemented method that determines the reversion state of each self-encrypting drive and uses predefined reversion keys stored within the storage array to revert drives to a factory-default state, allowing for automatic reinitialization regardless of the storage array's state, using either the running or secondary operating system environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical access to drive labels is required for reversion, then drive security is maintained, but reinitialization efficiency deteriorates

Engineering Contradiction:
Improvedrive securityVSAvoidreinitialization efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a copy of the reversion key and stores it in a predefined area within the storage array itself. This copy can be automatically retrieved during reinitialization without requiring physical access to the drive labels, thus resolving the contradiction between maintaining security through physical access requirements and improving reinitialization efficiency through automated key retrieval.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces an intermediary mechanism - a predefined area within the storage array that stores a copy of the reversion key. This intermediary allows the system to automatically access reversion keys during reinitialization without requiring direct physical access to drive labels, thereby improving efficiency while maintaining the security model.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manual reversion of each drive is performed, then drive security is maintained, but time consumption increases

Engineering Contradiction:
Improvedrive securityVSAvoidreinitialization time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent merges the reversion key access functionality into the storage array's predefined area. By combining the key storage and retrieval operations into a unified automated process within the storage array, multiple drive reversion operations can be performed simultaneously or sequentially without manual intervention for each drive, reducing total reinitialization time while maintaining security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary action by pre-storing copies of reversion keys in a predefined area within the storage array during manufacturing or initialization. This preliminary preparation eliminates the need for manual key retrieval during reinitialization, significantly reducing time consumption while maintaining the security integrity of the drives.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If physical access to storage array is required, then drive authentication is secure, but operational flexibility deteriorates

Engineering Contradiction:
Improvedrive authenticationVSAvoidoperational flexibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the storage array to automatically retrieve and use stored reversion keys from its own predefined area during reinitialization. The system serves itself by performing the authentication and reversion operations without requiring external physical access or manual intervention, thus maintaining secure authentication while dramatically improving operational flexibility.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary - a predefined area within the storage array that stores reversion keys. This intermediary enables automated authentication and reversion operations to be performed remotely or without physical access to the storage array, resolving the contradiction between secure authentication requiring physical access and operational flexibility requiring remote access capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If multiple drives are reverted individually, then each drive's security is maintained, but process complexity increases

Engineering Contradiction:
Improvedrive securityVSAvoidreinitialization process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the reversion operations for multiple drives into a single unified process. By storing reversion keys for multiple drives in a predefined area within the storage array and retrieving them simultaneously during reinitialization, the system eliminates the need for separate manual reversion operations for each drive, reducing process complexity while maintaining individual drive security.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent performs preliminary action by pre-organizing and pre-storing reversion keys for multiple drives in a structured predefined area within the storage array. This preliminary organization enables the system to automatically retrieve and apply the correct keys during reinitialization without requiring complex manual procedures for each drive, simplifying the overall process while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11681450B2System and method for self-encrypting drive reversion during re-initialization of a storage array
Publication Date: 2023.06.20 EMC IP HLDG CO LLC
  • US11681450B2 patent drawing
  • US11681450B2 patent drawing
  • US11681450B2 patent drawing

AI summary

A method, computer program product, and computing system for receiving a re-initialization operation request for a storage array, the storage array including a plurality of self-encrypting drives. A reversion state may be determined for each self-encrypting drive of the plurality of self-encrypting drives. In response to determining that at least one self-encrypting drive is in an unreverted state, at least one predefined reversion key for reverting the at least one self-encrypting drive from a predefined area of the storage array may be accessed. Each self-encrypting drive of the plurality of self-encrypting drives in the unreverted state may be reverted to a reverted state using the at least one predefined reversion key.