Storage Device Authentication Upon Standby Resume
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing devices with hardware-based authentication mechanisms face challenges in resuming from standby mode without compromising data security, as existing systems often lack the necessary functionality to properly authenticate access due to limited BIOS or OS functions during this state.
Innovation Solution
Implementing a caching mechanism for authentication data on the host computing device before entering standby mode, allowing the storage device to be locked and unlocked securely upon resuming, with optional re-authentication processes to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a storage device includes hardware-based authentication mechanisms to secure data, then data security is improved, but the ability to resume from standby mode is worsened due to limited BIOS or OS functions
Solution Approach 1:
The host computing device caches authentication data in memory before entering standby mode. This preliminary action ensures that when the system resumes, the authentication data is already available, allowing the storage device to be unlocked without requiring full authentication functionality during the resume process.
Solution Approach 2:
The patent introduces an intermediary authentication mechanism where the host computing device acts as a mediator between the user and the storage device. The host caches and manages authentication data, transmitting it to the storage device upon resume, thereby bridging the gap between limited standby functionality and security requirements.
2Reliability
If the storage device locks itself upon entering standby mode to maintain security, then data security is improved, but the convenience of quick resume is worsened
Solution Approach 1:
Authentication data is cached in advance before standby mode begins. This allows the storage device to quickly unlock upon resume without requiring time-consuming authentication processes, thus reducing the loss of time while maintaining security.
Solution Approach 2:
The system skips the normal authentication interaction during resume by using pre-cached authentication data. The storage device rapidly transitions from locked to unlocked state by accepting the cached credentials, effectively rushing through what would otherwise be a time-consuming authentication process.
3Ease of operation
If authentication data is cached on the host computing device to enable standby resume, then ease of operation is improved, but the risk of unauthorized access is worsened
Solution Approach 1:
The storage device monitors for re-transmission of authentication data within a predetermined time window after resume. This feedback mechanism ensures that the cached authentication data is being actively used by the legitimate host, and if not re-transmitted within the expected timeframe, the storage device re-locks, preventing unauthorized access.
Solution Approach 2:
The system implements periodic re-authentication where the host computing device must re-transmit authentication data at regular intervals after resume. This periodic verification ensures that the authentication credentials are still valid and being used by the authorized host, reducing the risk of unauthorized access to cached data.
Data Source
AI summary
Example embodiments disclosed herein relate to a storage device. The storage device may include a mechanism that monitors for receipt of cached authentication data from a host computing device upon resuming operation from a standby mode of the host computing device. The storage device may further include a mechanism that unlocks the storage device in response to receipt of the cached authentication data from the host computing device. In addition, the storage device may include a mechanism that monitors for receipt of re-authentication data and a mechanism that locks the storage device when a predetermined period of time has passed since resuming operation from the standby mode without receipt of the re-authentication data. Related computing devices, methods, and machine-readable storage media are also disclosed.


