Multi-role Data Storage Access via Internal Cryptographic Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage devices face challenges in user-friendly encryption management, as setup processes are cumbersome for unskilled users, and existing solutions for access control are impractical for devices moved between host systems, leading to insecure storage and underutilization of encryption technology.

Innovation Solution

A data storage device that allows definition of multiple roles using cryptographic keys stored internally, with distinct user and manager keys for access control, enabling secure decryption and configuration management without relying on external operating systems or access control lists.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple roles are defined using external operating systems and access control lists, then access control functionality is achieved, but the solution becomes impractical for devices moved between different host computer systems

Engineering Contradiction:
Improveportability across host systemsVSAvoidaccess control implementation
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the access control functionality from the external operating system environment and relocates it entirely within the data storage device. The device now contains its own role definition mechanism, cryptographic key storage, and access control logic, making it independent of external OS implementations and portable across different host systems.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces cryptographic keys as an intermediary mechanism between the device and access control functionality. Rather than relying on OS-level access control lists, the system uses cryptographic authentication to mediate access, where authorized devices prove their identity through cryptographic challenges, enabling role-based access without external OS dependencies.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is implemented with stored keys and passwords, then data security is improved, but the setup process becomes cumbersome and complicated for technically unskilled users

Engineering Contradiction:
Improvedata securityVSAvoidsetup process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service authentication where the data storage device automatically manages cryptographic keys and performs authentication challenges without requiring user configuration. Authorized devices are automatically recognized through cryptographic verification, eliminating the need for manual password setup while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical system of manual password and key management with an automated cryptographic authentication mechanism. The system uses challenge-response protocols and cryptographic key exchange to automatically establish secure access, substituting user-friendly automated processes for complex manual security configuration.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If cryptographic keys are stored securely in the device, then access control security is improved, but the complexity of key management increases

Engineering Contradiction:
Improveaccess control securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the cryptographic key management into distinct roles (user role and manager role) with different cryptographic keys. This segmentation allows different levels of access control and simplifies key management by separating concerns: user keys for data access and manager keys for configuration access, reducing the complexity of managing a single comprehensive key system.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11334677B2Multi-role unlocking of a data storage device
Publication Date: 2022.05.17 SANDISK TECHNOLOGIES LLC
  • US11334677B2 patent drawing
  • US11334677B2 patent drawing
  • US11334677B2 patent drawing

AI summary

Disclosed herein is a data storage device comprising a data path, an access controller, and a data store. The data path comprises a data port configured to transmit data between a host computer system and the data storage device; a non-volatile storage medium configured to store encrypted user content data; and a cryptography engine connected between the data port and the storage medium and configured to use a cryptographic key to decrypt the encrypted user content data stored on the storage medium in response to a request from the host computer system. The access controller is configured to store on the data store multiple entries associated with multiple respective registered devices. The multiple entries comprise authorization data indicative of cryptographic keys that selectively provide user access or manager access for each of the multiple registered devices.