Storage Apparatus Logical Partition Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing storage apparatuses using the FAT file system are vulnerable to unauthorized data access when interconnected with external systems, as they lack effective security measures to prevent unintended access to confidential data.

Innovation Solution

A storage apparatus with a logic controller and authentication module that partitions the storage region into normal and secure areas, allowing access only to previously specified external systems, using a table to differentiate between authentic and false entries and setting access modes to restrict unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a storage apparatus uses the FAT file system for compatibility with external systems, then ease of operation and adaptability are improved, but security against unauthorized data access deteriorates

Engineering Contradiction:
Improvecompatibility with external systemsVSAvoidunauthorized data access
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The storage region is divided into multiple logical partitions, with each partition containing normal areas and secure areas. This segmentation allows different access controls to be applied to different data regions, enabling compatibility with external systems for normal areas while protecting sensitive data in secure areas from unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An authentication module is introduced as an intermediary between external systems and the storage apparatus. This module verifies host identities and controls access to secure areas, allowing the storage apparatus to maintain FAT file system compatibility while preventing unauthorized access through the mediating authentication layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If arbitrary access to data is allowed for compatibility with external systems, then ease of operation is improved, but data security deteriorates

Engineering Contradiction:
Improveaccessibility to external systemsVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The storage apparatus dynamically adjusts access modes based on host authentication results. When a host is authenticated, the apparatus switches to a mode that allows access to secure areas; when unauthenticated, it restricts access to normal areas only. This dynamic behavior maintains ease of operation for authorized users while ensuring data security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication module changes access parameters (read-only, read-write, or no access) to secure areas based on host verification results. This parameter change mechanism allows the system to maintain FAT file system compatibility and ease of operation while controlling data security through adjustable access parameters.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7900012B2Secure storage apparatus and method for controlling the same
Publication Date: 2011.03.01 PHISON ELECTRONICS
  • US7900012B2 patent drawing
  • US7900012B2 patent drawing
  • US7900012B2 patent drawing

AI summary

The present invention discloses a storage apparatus in communication with one or more external systems, including at least one storage region, at least one logical partition formed by using a first part of the storage region for storing data, and a logic controller, provided with an authentication module for setting one access mode for controlling access to the logical partition according to the access mode when a vendor command from the external system requesting access to the logical partition is received.