Storage Device HSM Firmware Key Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage systems face challenges in securing large volumes of data over long periods, as cryptographic keys used for encryption can be compromised, leading to unauthorized access due to their need to be accessed by multiple components, increasing the risk of exposure.
Innovation Solution
Incorporating a storage device with cryptographic capabilities, enabling it to function as a hardware security module (HSM), where internal keys are securely stored and managed within the device, allowing for secure processing and encryption/decryption operations without exposing keys to other components, and using firmware to transform existing storage devices into HSMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are stored and accessed by multiple components outside the storage device, then data encryption functionality is enabled, but the risk of key exposure and unauthorized access increases
Solution Approach 1:
The patent extracts the cryptographic key storage and management functionality from external components and relocates it into the storage device itself. The storage device now contains dedicated key storage memory and cryptographic processing units, isolating keys from external access points and reducing the attack surface for potential key compromise.
Solution Approach 2:
The patent introduces an intermediary cryptographic processing unit within the storage device that acts as a secure gateway between external data access requests and the encrypted data. This intermediary handles all cryptographic operations internally, allowing external components to access encrypted data without ever exposing the actual cryptographic keys.
2Adaptability or versatility
If cryptographic keys are managed externally, then key updates and rotations can be performed, but the complexity of security management increases over time
Solution Approach 1:
The patent implements self-service key management capabilities within the storage device, including automatic key generation, storage, rotation, and destruction. The device autonomously manages its own cryptographic keys through integrated key management software and hardware security modules, eliminating the need for external key management infrastructure and reducing operational complexity.
3Ease of manufacture
If existing storage devices are transformed into HSMs using firmware, then cryptographic functionality is added without hardware modification, but the device's dual functionality increases complexity
Solution Approach 1:
The patent designs the storage device with multi-functionality, allowing it to operate both as a conventional storage device and as a hardware security module. The device includes separate processing units and memory spaces that enable it to perform standard storage operations while simultaneously providing cryptographic key management and security processing, effectively serving multiple purposes within a single device architecture.
Data Source
AI summary
A storage device can include processing and cryptographic capability enabling the device to function as a hardware security module (HSM). This includes the ability to encrypt and decrypt data using a cryptographic key, as well as to perform processing using such a key, independent of whether that processing involves data stored on the device. An internal key can be provided to the drive, whether provided before customer software access or received wrapped in another key, etc. That key enables the device to perform secure processing on behalf of a user or entity, where that key is not exposed to other components in the network or environment. A key may have specified tasks that can be performed using that key, and can be discarded after use. In some embodiments, firmware is provided that can cause a storage device to function as an HSM and/or processing device with cryptographic capability.


