Storage Controller Data Protection via Passkey Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional host-level data protection methods are inadequate for ensuring the security of mission-critical and personal data, as they can lead to inadvertent data overlays, are resource-intensive, and often fail to detect unauthorized access, resulting in untraceable data corruption and potential loss.

Innovation Solution

A data protection apparatus and system that operates independently of the host, utilizing a logic unit with modules like a monitor, verification, and write module to enforce protection protocols by requiring a passkey for accessing protected areas on a storage device, preventing unauthorized writes and tracing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If host-level data protection methods are used, then data access flexibility is maintained, but data security deteriorates due to inadvertent data overlays and unauthorized access

Engineering Contradiction:
Improvedata securityVSAvoidinadvertent data overlays
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a storage controller as an intermediary between the host and storage medium. The controller includes a protection apparatus with logic that intercepts and validates write commands before they reach the storage medium. This intermediary layer enforces protection protocols and verifies passkeys, preventing inadvertent data overlays while maintaining transparent data access for authorized operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The protection apparatus performs preliminary validation of write commands by checking passkeys before allowing data to be written to protected areas. The logic unit verifies authorization in advance, and only permits writes from authorized hosts. This preliminary action prevents unauthorized or inadvertent writes before they can corrupt protected data.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If software-based host protection is implemented, then data protection capability is provided, but system performance deteriorates due to severe impact on processing speed

Engineering Contradiction:
Improvedata protection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces software-based protection mechanisms with hardware-based logic in the storage controller. The protection apparatus is implemented as dedicated logic (potentially in firmware or hardware circuits) within the controller, rather than as software running on the host. This substitution eliminates the severe performance impact of software-based solutions while maintaining robust data protection capabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If protected areas are designated on storage medium, then data security is improved, but device complexity increases due to management overhead

Engineering Contradiction:
Improvedata securityVSAvoidprotection management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The protection apparatus automatically manages protected areas without requiring manual administrator intervention for each operation. The logic unit autonomously validates passkeys, enforces protection protocols, and tracks authorized hosts. This self-service capability reduces administrative overhead and simplifies management while maintaining security.

Inventive Principle:
Principle #25Self-service

4Reliability

If passkey verification is required for write commands, then unauthorized access is prevented, but ease of operation deteriorates due to additional access requirements

Engineering Contradiction:
Improveaccess control securityVSAvoiddata access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments data storage into protected and unprotected areas on the storage medium. Write commands to unprotected areas require no passkey and proceed normally, maintaining ease of operation. Write commands to protected areas require passkey verification, providing security where needed. This segmentation allows the system to balance security and convenience by applying protection only where necessary.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS7464219B2Apparatus, system, and storage medium for data protection by a storage device
Publication Date: 2008.12.09 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7464219B2 patent drawing
  • US7464219B2 patent drawing
  • US7464219B2 patent drawing

AI summary

An apparatus, system, and storage medium are disclosed for utilizing data protection by a storage device to minimize loss of sensitive data on a storage medium. The apparatus includes a monitor module, a verification module, and a process module. The monitor module recognizes a write-type command from a host connected to an electronic data storage device. The verification module determines a presence of a passkey associated with the write-type command. The process module processes the write-type command according to the determination of the presence of the passkey. The apparatus, system, and storage medium provide protection of sensitive data at the device level so that a designated protected area on the electronic data storage device is protected against an inadvertent data overlay.