In Situ Data Storage Device Authentication and Diagnostic Repair

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage device access control systems face challenges such as compromised security due to shared credentials, maintenance burdens for unique device credentials, and inefficiencies in remote authentication and diagnostic repair, especially in customer environments with unreliable network connections and high costs for physical device removal and replacement.

Innovation Solution

An apparatus and method for in situ authentication and diagnostic repair, involving a multi-device data storage array that detects error conditions, establishes user authentication levels, and executes diagnostic tools using challenge values and symmetric key authentication, allowing for in situ evaluation and decision-making on device repair or replacement without physical removal.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical device removal and replacement is used for diagnostic repair, then device security and control are maintained, but operational efficiency and cost effectiveness deteriorate due to physical removal requirements and replacement logistics

Engineering Contradiction:
Improvedevice securityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent replaces the mechanical system of physical device removal and replacement with an electronic/digital system. Diagnostic tools and authentication mechanisms are delivered and executed remotely through network connections, eliminating the need for physical intervention while maintaining security control through cryptographic authentication protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a remote authentication server as an intermediary between the host device and the data storage device. This intermediary enables secure diagnostic operations by mediating the authentication process through challenge-response protocols and credential verification, allowing remote access without physical device handling.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique device credentials are implemented for each data storage device, then security is improved, but device complexity and maintenance burden increase due to credential management requirements

Engineering Contradiction:
ImprovesecurityVSAvoidcredential management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication mechanism where a single credential structure (secret key + device identifier) serves multiple data storage devices in a multi-device array. The authentication server handles credential verification for all devices using the same protocol, eliminating the need for separate credential management systems for each device while maintaining unique security credentials.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

Each data storage device autonomously generates its own unique credential (secret key and device identifier) without requiring external provisioning. The device independently participates in the challenge-response authentication process, managing its own credentials locally while the authentication server verifies them, reducing centralized credential management complexity.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If shared credentials are used for data storage devices, then ease of operation is improved, but security deteriorates due to compromised credential exposure

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the authentication credentials into two distinct components: a secret key and a device identifier. This segmentation allows each data storage device to have unique credentials while using the same authentication protocol. The challenge-response mechanism further segments the authentication process into multiple steps, ensuring that even if one component is compromised, the entire credential set remains secure.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9729534B2In situ device authentication and diagnostic repair in a host environment
Publication Date: 2017.08.08 SEAGATE TECH LLC
  • US9729534B2 patent drawing
  • US9729534B2 patent drawing
  • US9729534B2 patent drawing

AI summary

Apparatus and method for in situ authentication and diagnostic repair of a data storage device in a multi-device user environment. In accordance with some embodiments, the method includes detecting an error condition associated with a selected data storage device in the multi-device user environment. A first level of user authentication is established by providing a challenge value generated by the selected data storage device to a remote device over a network associated with the selected data storage device. A first diagnostic tool stored on the selected data storage device is executed responsive to receipt of the first level of user authentication. A second level of user authentication is established by providing a second challenge value generated by the selected data storage device to the remote device. An output from the first diagnostic tool is used to execute a second diagnostic tool stored on the selected data storage device.