Selective Encryption for Data Storage Cartridges
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Automated data storage libraries face challenges in selectively securing data on removable media, requiring a system that can encrypt data at different levels without affecting library performance.
Innovation Solution
A method within a data storage drive that receives user-defined encryption policies, matches cartridge identifiers with stored encryption keys, and requests encryption keys from a key server to selectively encrypt data, allowing for flexible security levels across different cartridges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data on all removable media is encrypted to the same high security level, then data security and legal liability protection are improved, but system complexity and performance overhead increase
Solution Approach 1:
The patent implements selective encryption where different data cartridges can have different encryption policies applied to them. The system assigns encryption keys and policies based on specific cartridge identifiers rather than uniformly encrypting all data. This allows critical data to receive high-level encryption while less sensitive data uses simpler or no encryption, thereby improving security where needed without unnecessarily increasing system complexity across the entire library.
2Adaptability or versatility
If selective encryption is implemented with different security levels for different cartridges, then flexibility and adaptability are improved, but key management complexity and processing time increase
Solution Approach 1:
The system pre-assigns encryption keys and policies to specific data cartridges during library initialization or cartridge insertion, storing these assignments in an encryption policy table. When data needs to be encrypted, the system simply retrieves the pre-determined key and policy for that cartridge rather than making security decisions in real-time. This preliminary setup enables flexible, cartridge-specific encryption policies to be implemented without incurring significant processing delays during actual data operations.
3Reliability
If encryption is applied to all data in the library, then overall data protection is improved, but library performance and accessibility are degraded
Solution Approach 1:
The patent implements partial encryption by applying encryption selectively only to specific data cartridges that require protection, rather than encrypting all data in the library. The system evaluates each cartridge's security requirements and applies appropriate encryption only where necessary. This partial approach maintains strong data protection for sensitive information while avoiding the performance degradation that would result from encrypting the entire library, thereby preserving overall library accessibility and operational efficiency.
Data Source
AI summary
In an automated data storage library, selective encryption for data stored or to be stored on removable media is provided. One or more encryption policies are established, each policy including a level of encryption, one or more encryption keys and the identity of one or more data cartridges. The encryption policies are stored in a policy table and the encryption keys are stored in a secure key server. A host requests access to a specified data cartridge and the cartridge is transported from a storage shelf in the library to a storage drive. Based on the identity of the specified cartridge, the corresponding encryption policy is selected from the table and the appropriate encryption key is obtained from the key server. The storage drive encrypts data in accordance with the key and stores the data on the media on an encryption table within the specified data cartridge.


