Self-Encrypting Module with Embedded Wireless Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing self-encrypting drives (SEDs) rely on host computers for user authentication, making them susceptible to hacking through communication channels and requiring dependency on host architecture and operating systems, which compromises security.

Innovation Solution

A self-encrypting module with embedded wireless user authentication that operates independently of host devices, using a radiofrequency transceiver for user authentication and maintaining encryption keys within the authentication subsystem, ensuring that authentication information is never accessible via communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If self-encrypting drives rely on host computers for user authentication, then authentication can be performed using host resources, but security is compromised due to susceptibility to hacking through communication channels and dependency on host architecture

Engineering Contradiction:
Improveauthentication capabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication function is segmented from the host system and embedded directly into the storage device. The authentication subsystem is a separate, self-contained module within the storage device that handles user authentication independently, eliminating the security vulnerability of communicating authentication data through host communication channels.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The storage device performs user authentication on its own without relying on host computer resources or software. The embedded authentication subsystem independently verifies user credentials and manages encryption keys, making the system self-sufficient for security-critical operations and eliminating dependency on host architecture.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If encryption keys are stored on the media in an encrypted form, then decryption is enabled, but the encryption key becomes readily available to those willing to circumvent the standard interface

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication subsystem extracts and retains control of the encryption key within the storage device itself. Rather than storing encrypted keys that can be accessed by circumventing the interface, the system keeps the decryption capability embedded in the authentication subsystem, which only releases decryption authorization after successful authentication through secure internal processes.

Inventive Principle:
Principle #2Taking out (Extraction)

3Ease of operation

If a password is used as the encryption key to encrypt the encryption key, then authentication is simplified, but the password becomes a single point of failure and the authentication subsystem becomes the means for managing encryption keys

Engineering Contradiction:
Improveauthentication simplicityVSAvoidauthentication subsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The authentication subsystem acts as an intermediary between user authentication and data decryption. It manages multiple encryption keys and authentication credentials internally, mediating between the user's password input and the actual decryption process. This intermediary layer adds complexity to the authentication subsystem but eliminates the need for users to directly manage multiple keys or complex authentication sequences.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11233630B2Module with embedded wireless user authentication
Publication Date: 2022.01.25 CLEVX LLC
  • US11233630B2 patent drawing
  • US11233630B2 patent drawing
  • US11233630B2 patent drawing

AI summary

Methods, systems, and computer programs are presented for a self-encrypting device (SED) incorporated into a host system. In one example, the host system includes a memory, a processor, a data channel in communication with the memory and the processor, and the SED. The SED comprises an authentication subsystem, a storage subsystem that stores encrypted data that is encrypted with an encryption key provided by the authentication subsystem, a radio frequency (RF) transceiver, and a data interface in electrical contact with the data channel. The data interface is locked from sending and receiving data until the SED is unlocked by the authentication subsystem with user-authentication information received via the RF transceiver.