Shippable Storage Device Security Model for Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The disparity between growing data storage capacity and transmission speed over networks leads to costly or time-consuming data transfer between storage facilities, and existing methods compromise data security during physical transfer, especially when using portable storage devices.

Innovation Solution

A shippable storage device equipped with encryption and secure data transfer protocols ensures secure data transfer by encrypting data multiple times with different keys, using a trusted platform module for authentication, and updating destination addresses dynamically, ensuring secure and efficient data transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If data is transferred over networks between storage facilities, then transmission speed is improved, but transmission speed is still too slow compared to storage capacity growth

Engineering Contradiction:
Improvedata transmission speedVSAvoiddata transfer time
Core Design Contradiction:
SpeedVSLoss of time

Solution Approach 1:

The patent replaces electronic network data transmission with physical mechanical transport of storage devices. Instead of transmitting data bits over networks, entire storage devices are shipped physically, achieving transfer speeds limited only by logistics rather than network bandwidth.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates physical copies of storage devices containing data. Multiple identical storage devices are manufactured with copies of the same data, allowing parallel shipping to multiple destinations simultaneously, effectively multiplying transfer speed.

Inventive Principle:
Principle #26Copying

2Speed

If data is physically moved on legacy hardware or stored by service providers, then transmission speed is improved, but data security and confidentiality are compromised

Engineering Contradiction:
Improvedata transfer speedVSAvoiddata security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent changes the security parameter from network-based authentication to physical unclonable function (PUF) based security. PUFs exploit inherent physical variations in hardware components to generate unique cryptographic identifiers that cannot be replicated, providing hardware-rooted security that persists through physical transport.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent combines multiple security mechanisms into a composite security system: PUF-based device identification, encrypted data storage, secure boot processes, and tamper detection. This layered composite approach ensures that compromise of one layer does not necessarily compromise overall security.

Inventive Principle:
Principle #40Composite materials

3Adaptability or versatility

If different types of storage devices are used by customers, then adaptability is improved, but device complexity and security management difficulty increase

Engineering Contradiction:
Improvestorage device compatibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal security framework based on PUFs that works across diverse storage device types. The secure boot process and PUF-based authentication provide a common security foundation that can be applied to SSDs, HDDs, flash storage, and other device types without requiring device-specific security implementations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9887998B2Security model for data transfer using a shippable storage device
Publication Date: 2018.02.06 AMAZON TECH INC
  • US9887998B2 patent drawing
  • US9887998B2 patent drawing
  • US9887998B2 patent drawing

AI summary

Data may be securely stored onto a shippable data storage device in order for the client data to be protected during shipment to the remote storage service provider. The service provider prepares a shippable storage device and ships it to the client. The service provider also sends client-keys and security information to the client, separate from the shippable storage device. A client-side data transfer tool authenticates the shippable storage device using the security information. The data transfer tool generates keys to encrypt the customer data. The data transfer tool then uses the client-keys received from the service provider to encrypt the tool-generated keys. The encrypted data and the encrypted tool-generated keys are transferred onto the shippable storage device. The shippable storage device is then shipped back to the service provider, which decrypts the tool-generated keys and the encrypted data before importing the data.