Storage Device Authenticity Verification Using Secret Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage security solutions fail to authenticate the authenticity of storage devices, allowing rogue or untrusted devices to compromise host devices and connected networks, potentially leading to malware distribution and data breaches.
Innovation Solution
A verification process using secret keys and single-use keys is implemented to authenticate storage devices, ensuring that only trusted devices can access data by generating and matching verification keys between the storage device and host device.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication is performed only for users and host devices, then user access control is achieved, but storage device authenticity cannot be verified allowing rogue devices to compromise the system
Solution Approach 1:
The patent implements preliminary authentication by generating verification keys (VKs) for storage devices before they are connected to the host system. These VKs are provisioned in advance during manufacturing and stored in secure elements within the storage devices. When a storage device is connected, the host can immediately verify its authenticity using the pre-provisioned VKs, eliminating the need for complex runtime verification protocols and ensuring that only authorized devices can access the network.
2Object-affected harmful factors
If traditional authentication methods are used, then user credentials can be verified, but storage devices can still distribute malware and compromise networks
Solution Approach 1:
The patent introduces verification keys as an intermediary authentication mechanism between the host device and storage device. Instead of directly trusting storage devices or relying solely on user credentials, the system uses VKs as a mediator that proves the storage device's identity and authorization. The host device verifies the storage device's VK before allowing any data transactions, creating a secure gate that blocks malware distribution while maintaining simple operation for authorized devices.
3Reliability
If all storage devices are allowed to access the network, then data availability is maximized, but untrusted devices can compromise host devices and connected systems
Solution Approach 1:
The patent implements self-service authentication where storage devices automatically present their verification keys to the host device upon connection, and the host device automatically verifies these keys without requiring manual intervention. This self-service mechanism ensures that only authenticated storage devices can access the network, blocking untrusted devices while maintaining high data access efficiency for authorized devices. The process is transparent to users and does not require complex security management.
Data Source
AI summary
Techniques for a host system or a user to verify the authenticity of a storage device or a logical sub-unit (e.g., a partition) of the storage device are disclosed. A storage device stores one or more first secret keys and a host device stores one or more second keys. A respective first secret key and a respective second key are used in a verification process that verifies the authenticity of the storage device prior to accessing the storage device.


