Self-Encrypting Drive Authentication Subsystem
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security systems for portable memory storage devices rely on host computers for authentication, making them susceptible to hacking and compromising encryption keys, as the encryption key is often stored on the media or transmitted through vulnerable communication channels.
Innovation Solution
A self-encrypting data security system with autonomous user authentication using a radiofrequency transceiver, independent of the host device and operating system, which maintains encryption keys securely within the authentication subsystem and transmits them only after valid user authentication, ensuring that the encryption key is never accessible outside the system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the encryption key is stored on the media or transmitted through communication channels for authentication, then the authentication process can be completed, but the system becomes susceptible to hacking and the encryption key may be compromised
Solution Approach 1:
The patent extracts the authentication function from the host computer system and places it entirely within the self-encrypting drive. The drive contains its own authentication subsystem with embedded identity information, allowing it to authenticate independently without transmitting encryption keys or authentication data through vulnerable host communication channels. This separation removes the authentication process from the attack surface of the host system.
Solution Approach 2:
The patent introduces an embedded identity information storage mechanism within the authentication subsystem that acts as a secure intermediary. Instead of transmitting encryption keys or authentication credentials through communication channels, the system uses embedded identity information that never leaves the drive, eliminating the intermediary transmission channel that could be hacked.
2Adaptability or versatility
If the authentication subsystem is dependent on the host computer architecture and operating system, then the system can leverage host resources for authentication, but the self-encrypting drive becomes susceptible to host-based security breaches
Solution Approach 1:
The patent extracts the authentication subsystem from dependency on host computer architecture and operating system. The authentication subsystem is fully embedded within the self-encrypting drive, containing its own logic and embedded identity information. This allows the drive to authenticate itself to any host without relying on host-specific authentication mechanisms, achieving architectural independence while maintaining host compatibility.
Solution Approach 2:
The patent creates a universal authentication subsystem that can operate independently of any specific host architecture or operating system. The embedded identity information and authentication logic are self-contained, allowing the drive to authenticate with any host system that supports the basic interface, making the authentication mechanism universally applicable while maintaining independence from any single host platform.
3Ease of operation
If communication channels are kept open to allow host access to the self-encrypting drive, then data transfer can occur, but the drive remains vulnerable to unauthorized access and hacking
Solution Approach 1:
The patent implements preliminary authentication action before any communication channel is opened or data transfer occurs. The authentication subsystem verifies the host's authorization credentials before establishing any data pathway. Only after successful authentication does the drive open communication channels, ensuring that unauthorized access attempts are blocked before they can exploit open channels.
Solution Approach 2:
The patent converts the potential harm of open communication channels into a benefit by using the authentication subsystem to monitor and control all channel activity. The same communication infrastructure that could be exploited for hacking is transformed into a controlled data transfer pathway, where the authentication subsystem continuously verifies legitimacy of access, turning the vulnerability of open channels into a secure data exchange mechanism.
Data Source
AI summary
Methods, systems, and computer programs are presented for remote management of self-encrypting managed devices (SEMDs) with embedded wireless authentication. One method includes providing a user interface to access a management server for managing users and devices. The SEMD is in wireless communication with the mobile device and is connection with the management server. Additionally, the management server checks user-authentication information of the user for unlocking access to the SEMD before is enabled to unlock the SEMD via mobile application of the mobile device. Further, the management server sends an unlock command to the mobile device based on the checking, the mobile device sending an unlock request to the SEMD via the wireless communication. The SEMD is configured to unlock the data channel to provide data access to encrypted storage in the SEMD.


