Storage Device HSM Firmware Key Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage systems face challenges in securing large volumes of data over long periods, as cryptographic keys used for encryption can be compromised, leading to unauthorized access due to their need to be accessed by multiple components, increasing the risk of exposure.

Innovation Solution

Incorporating a storage device with cryptographic capabilities, enabling it to function as a hardware security module (HSM), where internal keys are securely stored and managed within the device, allowing for secure processing and encryption/decryption operations without exposing keys to other components, and using firmware to transform existing storage devices into HSMs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored and accessed by multiple components outside the storage device, then data encryption functionality is enabled, but the risk of key exposure and unauthorized access increases

Engineering Contradiction:
Improvedata securityVSAvoidkey exposure risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the cryptographic key storage and management functionality from external components and relocates it into the storage device itself. The storage device now contains dedicated key storage memory and cryptographic processing units, isolating keys from external access points and reducing the attack surface for potential key compromise.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary cryptographic processing unit within the storage device that acts as a secure gateway between external data access requests and the encrypted data. This intermediary handles all cryptographic operations internally, allowing external components to access encrypted data without ever exposing the actual cryptographic keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If cryptographic keys are managed externally, then key updates and rotations can be performed, but the complexity of security management increases over time

Engineering Contradiction:
Improvekey management flexibilityVSAvoidsecurity management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements self-service key management capabilities within the storage device, including automatic key generation, storage, rotation, and destruction. The device autonomously manages its own cryptographic keys through integrated key management software and hardware security modules, eliminating the need for external key management infrastructure and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Ease of manufacture

If existing storage devices are transformed into HSMs using firmware, then cryptographic functionality is added without hardware modification, but the device's dual functionality increases complexity

Engineering Contradiction:
Improvedevice transformation easeVSAvoiddevice functionality complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent designs the storage device with multi-functionality, allowing it to operate both as a conventional storage device and as a hardware security module. The device includes separate processing units and memory spaces that enable it to perform standard storage operations while simultaneously providing cryptographic key management and security processing, effectively serving multiple purposes within a single device architecture.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11270006B2Intelligent storage devices with cryptographic functionality
Publication Date: 2022.03.08 AMAZON TECH INC
  • US11270006B2 patent drawing
  • US11270006B2 patent drawing
  • US11270006B2 patent drawing

AI summary

A storage device can include processing and cryptographic capability enabling the device to function as a hardware security module (HSM). This includes the ability to encrypt and decrypt data using a cryptographic key, as well as to perform processing using such a key, independent of whether that processing involves data stored on the device. An internal key can be provided to the drive, whether provided before customer software access or received wrapped in another key, etc. That key enables the device to perform secure processing on behalf of a user or entity, where that key is not exposed to other components in the network or environment. A key may have specified tasks that can be performed using that key, and can be discarded after use. In some embodiments, firmware is provided that can cause a storage device to function as an HSM and/or processing device with cryptographic capability.