Storage Device Challenge-Response Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current password-entry security processes for data storage devices, especially in servers and remotely located storage devices, are vulnerable to interception during reboot or state-changing events, requiring administrative oversight and are inconvenient and costly.
Innovation Solution
A secure authorization mechanism that uses Challenge-Response messages with obfuscated keying material and random numbers, allowing access to storage devices without user intervention, utilizing XOR operations and cryptographic functions to ensure secure access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If password-entry security processes are used for storage devices, then access control is provided, but the system becomes vulnerable to interception during reboot or state-changing events
Solution Approach 1:
The patent applies preliminary action by generating and storing a unique challenge value in the storage device before the reboot event occurs. This pre-generated challenge value is then used during the reboot process to authenticate the host system, preventing interception vulnerabilities by ensuring that even if passwords are transmitted during reboot, they cannot be intercepted or reused by unauthorized systems.
2Reliability
If administrative oversight is implemented for password-entry security, then security control is improved, but operational convenience and cost effectiveness deteriorate
Solution Approach 1:
The patent implements self-service by enabling the storage device to automatically perform security authentication during reboot events without requiring administrative intervention. The storage device uses its pre-generated challenge values to authenticate the host system and control access automatically, eliminating the need for IT personnel to manually oversee each reboot security process while maintaining strong security control.
3Ease of operation
If password transmission during reboot is allowed, then access to storage devices is enabled, but the system becomes susceptible to tapping and password interception
Solution Approach 1:
The patent uses an intermediary mechanism by introducing challenge-response authentication as a mediator between the host system and storage device during reboot. Instead of directly transmitting passwords, the system exchanges challenge values and responses that authenticate the host without exposing actual password information, preventing tapping and password interception while maintaining access capability.
4Reliability
If manual password-entry security processes are used, then access control is maintained, but productivity and operational efficiency deteriorate
Solution Approach 1:
The patent applies preliminary action by pre-generating and storing unique challenge values in the storage device before reboot events. This eliminates the need for manual password entry during each reboot, as the authentication process automatically uses the pre-generated challenge values, significantly improving operational efficiency while maintaining reliable access control.
Data Source
AI summary
A storage device features a processor and a random number generation which are communicatively coupled to a memory. The memory comprises an access control logic that is configured to (i) transmit a first message that comprises information associated with a random number generated by the random number generator and a first keying material, (ii) receive a second message in response to the first message, the second message comprises information generated using at least the random number, (iii) recover information from the second message, the recovered information comprises information generated using at least pre-stored keying material and a return value being based on the random number, (iv) compare the return value from the recovered information with the random number, and (v) alter an operating state of the storage device from a locked state to an unlocked state upon the return value matching the random number, the unlocked state allows one or more devices to control storage device including accessing stored content within the storage device.


