Multi-role Data Storage Access via Internal Cryptographic Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage devices face challenges in user-friendly encryption management, as setup processes are cumbersome for unskilled users, and existing solutions for access control are impractical for devices moved between host systems, leading to insecure storage and underutilization of encryption technology.
Innovation Solution
A data storage device that allows definition of multiple roles using cryptographic keys stored internally, with distinct user and manager keys for access control, enabling secure decryption and configuration management without relying on external operating systems or access control lists.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple roles are defined using external operating systems and access control lists, then access control functionality is achieved, but the solution becomes impractical for devices moved between different host computer systems
Solution Approach 1:
The patent extracts the access control functionality from the external operating system environment and relocates it entirely within the data storage device. The device now contains its own role definition mechanism, cryptographic key storage, and access control logic, making it independent of external OS implementations and portable across different host systems.
Solution Approach 2:
The patent introduces cryptographic keys as an intermediary mechanism between the device and access control functionality. Rather than relying on OS-level access control lists, the system uses cryptographic authentication to mediate access, where authorized devices prove their identity through cryptographic challenges, enabling role-based access without external OS dependencies.
2Reliability
If encryption is implemented with stored keys and passwords, then data security is improved, but the setup process becomes cumbersome and complicated for technically unskilled users
Solution Approach 1:
The patent implements self-service authentication where the data storage device automatically manages cryptographic keys and performs authentication challenges without requiring user configuration. Authorized devices are automatically recognized through cryptographic verification, eliminating the need for manual password setup while maintaining strong security.
Solution Approach 2:
The patent replaces the mechanical system of manual password and key management with an automated cryptographic authentication mechanism. The system uses challenge-response protocols and cryptographic key exchange to automatically establish secure access, substituting user-friendly automated processes for complex manual security configuration.
3Reliability
If cryptographic keys are stored securely in the device, then access control security is improved, but the complexity of key management increases
Solution Approach 1:
The patent segments the cryptographic key management into distinct roles (user role and manager role) with different cryptographic keys. This segmentation allows different levels of access control and simplifies key management by separating concerns: user keys for data access and manager keys for configuration access, reducing the complexity of managing a single comprehensive key system.
Data Source
AI summary
Disclosed herein is a data storage device comprising a data path, an access controller, and a data store. The data path comprises a data port configured to transmit data between a host computer system and the data storage device; a non-volatile storage medium configured to store encrypted user content data; and a cryptography engine connected between the data port and the storage medium and configured to use a cryptographic key to decrypt the encrypted user content data stored on the storage medium in response to a request from the host computer system. The access controller is configured to store on the data store multiple entries associated with multiple respective registered devices. The multiple entries comprise authorization data indicative of cryptographic keys that selectively provide user access or manager access for each of the multiple registered devices.


