Storage Controller Access Control for TCG Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional storage devices face challenges in complying with the Trusted Computing Group (TCG) standard, which prohibits access to the user authentication routine from the host device when it is not used, as the routine is often stored in a user area accessible by the host, allowing unauthorized access even after authentication.
Innovation Solution
A controller for a storage device that stores the user authentication routine in a predetermined area within the user area and includes an access controlling unit to permit access only when the routine is used, prohibiting access when it is not used, thereby ensuring compliance with the TCG standard by using a use flag to manage access permissions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the user authentication routine is stored in the user area to enable easy access and development, then the ease of operation and development is improved, but the security and compliance with TCG standard deteriorates because the host device can access the routine even when not used
Solution Approach 1:
The user area is segmented into multiple regions: a first region for storing the user authentication routine and a second region for storing the operating system. This segmentation allows the host device to access the routine when needed while maintaining the ability to prohibit access when not needed, resolving the contradiction between ease of access and security compliance.
Solution Approach 2:
The access control mechanism is made dynamic by allowing the host device to access the user authentication routine only when authentication is required, and prohibiting access when not required. This dynamic access control enables the system to comply with TCG standard while maintaining operational flexibility.
2Reliability
If the user authentication routine is stored in a separate special area to ensure security and TCG compliance, then the security is improved, but the device complexity increases due to requiring additional area management
Solution Approach 1:
The user area serves multiple functions: it stores both the user authentication routine and the operating system, and provides dynamic access control capabilities. This multi-functionality eliminates the need for separate special areas, reducing device complexity while maintaining security compliance.
Solution Approach 2:
The user authentication routine storage and operating system storage are merged into a single user area with internal region division. This merging simplifies the overall structure by eliminating the need for separate special areas while maintaining the security benefits through region-based access control.
3Adaptability or versatility
If access to the user authentication routine is always permitted from the host device to ensure operational flexibility, then the ease of operation is improved, but the security and TCG standard compliance deteriorates
Solution Approach 1:
The access permission to the user authentication routine is made dynamic rather than static. The system can adaptively permit access when authentication is required and prohibit access when not required, thereby achieving both operational flexibility and security compliance with TCG standard.
Solution Approach 2:
The access control parameter (permission state) is changed dynamically based on authentication requirements. By changing the access parameter from always-permitted to conditionally-permitted, the system achieves both adaptability and security compliance.
Data Source
AI summary
A controller of a storage device having a user area storing an operating system, the storage device developing the operating system stored in the user area on a host device in accordance with an access from the host device. The controller includes a user authentication routine storage controlling unit that stores a user authentication routine for executing user authentication before startup of the operating system, in a predetermined area inside the user area, and an access controlling unit that permits access to the predetermined area from the host device when the user authentication routine is used, while prohibiting access to the predetermined area from the host device when the user authentication routine is not used.


