Storage Device Host Authentication and Key Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing HDDs lack a reliable method to prevent data leakage when stolen, as encryption keys may not be erased in time if the HDD is detached before a remote instruction is received, and self-erasing HDDs require hardware modifications, making them difficult to integrate into existing systems.

Innovation Solution

A storage device with a switching unit that switches access between two storage areas, using a software module to authenticate the host device and grant access only when the device information matches, and erasing data by resetting the encryption key when authentication fails, conforming to TCG Opal SSC specifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote erasing of encryption key is implemented, then data leakage is prevented, but the encryption key may not be erased in time if the HDD is detached before the instruction is received

Engineering Contradiction:
Improvedata securityVSAvoidtime for key erasure
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a self-erasing function that automatically erases the encryption key under predetermined conditions (such as when the HDD is detached from the PC or when configuration between BIOS and HDD fails). This preliminary action ensures that the encryption key is erased before potential data leakage can occur, eliminating the timing issue associated with remote erasing instructions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If self-erasing function with hardware circuit is implemented, then data leakage is prevented, but hardware modification is required making it difficult to incorporate in existing HDDs

Engineering Contradiction:
Improvedata securityVSAvoidhardware modification
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the hardware circuit-based self-erasing function with a software module that runs on the HDD's existing controller. The software module monitors system conditions and automatically erases the encryption key when predetermined conditions are met, achieving the same security function without requiring any hardware modifications to existing HDDs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If encryption key is stored in HDD, then data can be accessed by multiple PCs, but data leakage risk increases when HDD is connected to unauthorized PCs

Engineering Contradiction:
ImprovePC compatibilityVSAvoiddata leakage risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements host device information storage in two separate storage areas within the HDD, with different access controls. The first storage area stores encryption keys accessible by any host, while the second storage area stores host device information that restricts access. This local quality differentiation allows the HDD to be adaptable to multiple PCs while preventing unauthorized access through selective data availability.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS8713250B2Storage device, data processing device, registration method, and recording medium
Publication Date: 2014.04.29 FUJITSU LTD
  • US8713250B2 patent drawing
  • US8713250B2 patent drawing
  • US8713250B2 patent drawing

AI summary

A storage device includes a switching unit which switches an access destination in a storage area between a first storage area and a second storage area in response to an access request from a host device; and a nonvolatile storage medium which stores a first host device information used to identify the host device in the second storage area, and a software module executed by a CPU provided in the host device, the software module comprising causing an authority grant unit which transmits a control signal for switching the access destination to the first storage area to the switching unit of the storage device, when the acquired first and second host device information are compared to find that the first and second host device information match with each other.