Storage Device Data Protection via Component ID Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for protecting sensitive information on data storage devices are inadequate, as they often require user interaction, are not automated, and fail to prevent unauthorized access when devices are relocated or repurposed, leading to potential data breaches.

Innovation Solution

A method involving the gathering and comparison of unique identification numbers from computer system components, stored in nonvolatile memory within the storage device, to verify system integrity and prevent access or erase data if changes are detected, ensuring secure operation even when the device is moved to a different system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data storage devices are made easily movable and interchangeable between systems, then device versatility and ease of operation improve, but data security and reliability deteriorate

Engineering Contradiction:
Improvedevice mobilityVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by storing unique identification numbers of computer system components (CPU, memory, I/O devices) in non-volatile memory of the storage device before the device is moved. This pre-stored information is later verified when the device is accessed in a different system, preventing unauthorized access without requiring real-time system verification.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If password protection is implemented at the BIOS level, then ease of operation improves, but reliability deteriorates because passwords can be bypassed when drives are moved to systems without BIOS password support

Engineering Contradiction:
Improvepassword protectionVSAvoidsecurity effectiveness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the security function from the BIOS level and relocates it to the storage device itself. By storing system component identification numbers directly in the drive's non-volatile memory and performing verification at the device level, the security mechanism is removed from BIOS dependency, making it portable and effective across different computer systems.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encryption is used to protect data, then data security improves, but device complexity and processing overhead increase

Engineering Contradiction:
Improvedata securityVSAvoidsecurity implementation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent changes the security parameter from encrypted data storage to stored identification numbers in non-volatile memory. Instead of encrypting all data on the device (which requires complex encryption algorithms and processing), the system stores simple identification numbers of system components and verifies them during access, providing security with minimal complexity and processing overhead.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8756390B2Methods and apparatuses for protecting data on mass storage devices
Publication Date: 2014.06.17 LENOVO GLOBAL TECHNOLOGIES SWITZERLAND INTERNATIONAL GMBH
  • US8756390B2 patent drawing
  • US8756390B2 patent drawing
  • US8756390B2 patent drawing

AI summary

Methods, apparatuses, and media to protect sensitive information in data storage devices are disclosed. Embodiments comprise a method of transmitting and receiving unique identification information of components of a computer system, comparing the information with previously saved information in the storage device, and not allowing access to the data if the information is substantially different. In some embodiments, the storage device may simply prevent access to the information. In other embodiments, the storage device may erase the information after detecting a change in the computer system. In other embodiments, the storage device may provide various options for effectively resetting the unique identification stored in the data storage device so that the device may be used in an altered system.