Storage Device Host Authentication and Key Erasure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing HDDs lack a reliable method to prevent data leakage when stolen, as encryption keys may not be erased in time if the HDD is detached before a remote instruction is received, and self-erasing HDDs require hardware modifications, making them difficult to integrate into existing systems.
Innovation Solution
A storage device with a switching unit that switches access between two storage areas, using a software module to authenticate the host device and grant access only when the device information matches, and erasing data by resetting the encryption key when authentication fails, conforming to TCG Opal SSC specifications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If remote erasing of encryption key is implemented, then data leakage is prevented, but the encryption key may not be erased in time if the HDD is detached before the instruction is received
Solution Approach 1:
The patent implements a self-erasing function that automatically erases the encryption key under predetermined conditions (such as when the HDD is detached from the PC or when configuration between BIOS and HDD fails). This preliminary action ensures that the encryption key is erased before potential data leakage can occur, eliminating the timing issue associated with remote erasing instructions.
2Reliability
If self-erasing function with hardware circuit is implemented, then data leakage is prevented, but hardware modification is required making it difficult to incorporate in existing HDDs
Solution Approach 1:
The patent replaces the hardware circuit-based self-erasing function with a software module that runs on the HDD's existing controller. The software module monitors system conditions and automatically erases the encryption key when predetermined conditions are met, achieving the same security function without requiring any hardware modifications to existing HDDs.
3Adaptability or versatility
If encryption key is stored in HDD, then data can be accessed by multiple PCs, but data leakage risk increases when HDD is connected to unauthorized PCs
Solution Approach 1:
The patent implements host device information storage in two separate storage areas within the HDD, with different access controls. The first storage area stores encryption keys accessible by any host, while the second storage area stores host device information that restricts access. This local quality differentiation allows the HDD to be adaptable to multiple PCs while preventing unauthorized access through selective data availability.
Data Source
AI summary
A storage device includes a switching unit which switches an access destination in a storage area between a first storage area and a second storage area in response to an access request from a host device; and a nonvolatile storage medium which stores a first host device information used to identify the host device in the second storage area, and a software module executed by a CPU provided in the host device, the software module comprising causing an authority grant unit which transmits a control signal for switching the access destination to the first storage area to the switching unit of the storage device, when the acquired first and second host device information are compared to find that the first and second host device information match with each other.


