Storage Device Controller Data Protection Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

External storage devices are vulnerable to data deletion, modification, or destruction due to system vulnerabilities or malicious programs when connected to a host, with existing solutions failing to provide effective protection during the initial connection period.

Innovation Solution

A data protection method involving a controller in the storage device that detects the need for protection upon connection, modifies the writing destination to prevent data from being written to the storage unit, and filters commands to redirect data to an internal memory or control chip, ensuring data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the external storage device is connected to the host, then the user can access and use the storage device, but the data in the storage device may be deleted, modified or destroyed by system vulnerabilities or malicious programs

Engineering Contradiction:
Improveaccessibility of storage deviceVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by activating a protection mechanism that monitors and controls write operations to the storage device during an initial time period after connection. This preemptive approach establishes a safe operating window before the device is fully recognized by the host system, preventing malicious or erroneous write operations from corrupting data while still allowing legitimate access.

Inventive Principle:
Principle #10Preliminary action

2Speed

If the host system recognizes the storage device quickly, then the user experience is improved, but the storage device becomes vulnerable to malicious programs during this recognition period

Engineering Contradiction:
Improvedevice recognition speedVSAvoidmalicious program impact
Core Design Contradiction:
SpeedVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary protection mechanism that acts as a buffer between the host system and the storage device during the vulnerable recognition period. This intermediary layer monitors incoming write operations and blocks potentially harmful operations while allowing legitimate ones through, thus mediating the interaction between the host and storage device to prevent malicious programs from exploiting the recognition vulnerability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If traditional protection methods are used, then data security may be improved, but the convenience and portability of external storage devices are reduced

Engineering Contradiction:
Improvedata protectionVSAvoidportability and convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service by enabling the storage device to autonomously activate its own protection mechanism upon connection to a host system. The device automatically enters a protected state during the initial recognition period without requiring user intervention or external security software, thus maintaining data security while preserving the portability and ease of use that characterize external storage devices.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11144217B2Data protection method and associated storage device
Publication Date: 2021.10.12 JMICRON
  • US11144217B2 patent drawing
  • US11144217B2 patent drawing

AI summary

The present invention provides a data protection method and storage device. The data protection method includes: (A): during an initial period after the storage device is connected to a host, detecting the storage device and determining whether the storage device needs to be performed with data protection; (B): when the storage device needs to be performed with data protection in Step (A), modifying a predetermined writing destination that the host writes data to a storage unit of the storage device, to make the data from the host be written to another writing destination rather than being written to said writing destination; or writing the data from the host into a control chip or a bridge chip of an inner memory or an inner register, rather than writing the data from the host into the storage device; and (C): reporting to the host that the writing operation is completed.