Data Storage Controller PIN Segmentation for Secure Initialization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data storage apparatuses face challenges in securely managing personal identification data, particularly in scenarios where users forget their PINs, leading to potential data leakage and unauthorized access, as existing solutions lack robust mechanisms for initialization and protection state management.

Innovation Solution

A data storage apparatus with a controller that includes a personal identification data manager, access controller, initialization processor, and authorization processor, which manages different types of PINs (SID, Admin, User, PSID, LSID, MSID) to control data protection functions, ensuring secure initialization and protection state transitions, and limits access to prevent unauthorized data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If personal identification data for initialization is provided to allow users to reset forgotten PINs, then user convenience is improved, but data security deteriorates due to potential misuse by unauthorized users

Engineering Contradiction:
Improveuser convenienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The personal identification data is segmented into two distinct types: first personal identification data (for initialization only) and second personal identification data (for both initialization and activation). This segmentation allows the system to provide different access levels for different operational needs, enabling users to reset forgotten PINs while maintaining security controls over data activation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different authorization rules are applied to different types of personal identification data. First personal identification data is restricted to initialization operations only, while second personal identification data permits both initialization and activation. This local quality approach ensures that convenience is provided where needed (resetting PINs) while security is maintained where critical (preventing unauthorized activation).

Inventive Principle:
Principle #3Local quality

2Reliability

If the data protection function is made robust to prevent unauthorized access, then data security is improved, but system complexity increases due to multiple PIN types and authorization levels

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization mechanism is segmented into distinct authorization processors: a first authorization processor for verifying first personal identification data and a second authorization processor for verifying second personal identification data. This segmentation creates a modular system where each processor handles specific authorization tasks, making the complex security system more manageable and maintainable while preserving strong security controls.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The personal identification data manager is designed to universally manage multiple types of personal identification data (first and second types) using a unified management approach. This multi-functionality allows the same management component to handle different PIN types with different authorization rules, reducing overall system complexity by avoiding the need for separate management systems for each PIN type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11232044B2Data storage apparatus, data processing system, and data processing method
Publication Date: 2022.01.25 KIOXIA CORP
  • US11232044B2 patent drawing
  • US11232044B2 patent drawing
  • US11232044B2 patent drawing

AI summary

According to one embodiment, a data storage apparatus includes a controller with a data protection function. The controller manages first and second personal identification data. The first personal identification data only includes authority to request inactivation of the data protection function. The second personal identification data includes authority to request inactivation of the data protection function and activation of the data protection function. The controller permits setting of the first personal identification data, when the second personal identification data is used for successful authentication and the first personal identification data is an initial value, or when the data protection function is in an inactive state.