Storage Device Cryptography Engine Key Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage devices with encryption technologies are cumbersome for technically unskilled users to set up, and often insecurely store keys and passwords, leading to underutilization of encryption features and exposure of confidential data.

Innovation Solution

A data storage device with a cryptography engine and an access controller that uses a cryptographic key to decrypt user content data, and generates multiple manager device records to authorize devices for unlocking the storage device securely.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to secure data storage, then data security is improved, but setup complexity and user difficulty increase

Engineering Contradiction:
Improvedata securityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically generates cryptographic key pairs and manages encryption/decryption operations without requiring user intervention. The computing device performs self-service by autonomously handling key generation, storing private keys in secure memory, and managing the encryption process, thereby eliminating complex manual setup while maintaining strong security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary architecture where a separate cryptography engine and secure memory module mediate between the user and the encryption process. This intermediary layer handles the complexity of key management and cryptographic operations, presenting a simplified interface to users while ensuring robust security through specialized hardware components

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If traditional key management is used, then encryption functionality is provided, but key storage security deteriorates

Engineering Contradiction:
Improveencryption functionalityVSAvoidkey storage security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the key management architecture into distinct functional components: a cryptography engine for key generation, secure memory for private key storage, and separate processing units for encryption operations. This segmentation isolates sensitive cryptographic materials from general processing, preventing unauthorized access while maintaining encryption versatility

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a copying mechanism where public keys are freely distributable for encryption operations, while private keys remain securely stored in protected memory. Multiple copies of public keys can be shared across different systems, enabling versatile encryption functionality, whereas the private key copies are restricted to secure storage, ensuring key storage security

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12225111B2Authorization requests from a data storage device to multiple manager devices
Publication Date: 2025.02.11 SANDISK TECHNOLOGIES LLC
  • US12225111B2 patent drawing
  • US12225111B2 patent drawing
  • US12225111B2 patent drawing

AI summary

Disclosed herein is a data storage device. A data port transmits data between a host computer system and the data storage device. A non-volatile storage medium stores encrypted user content data and a cryptography engine connected between the data port and the storage medium uses a cryptographic key to decrypt the encrypted user content data. Multiple manager device records each comprise a first key identical for each of the records, and a second key that different for each of the records. The controller generates an authorization request using the first key and receives a response to the request generated by a manager device. The response is specific to that manager device. The controller uses the response to locate the record; decrypts the located manager device record to obtain key data; and generates configuration data based on the key data to register the device.