Storage Device PIN Authentication and Secure Data Erasure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-capacity storage devices require enhanced security measures to ensure data erasure and protection, particularly in scenarios where multiple users share a single device and data needs to be securely reset or erased.

Innovation Solution

A storage device configuration with a receiver and transmitter for data erasure mechanisms, utilizing PIN-based authentication and authorization to manage access and execute data erasure commands, including overwrite, block erasure, unmap, reset write pointers, and crypto erasure, ensuring secure data deletion and initialization of PINs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security functions are implemented for large-capacity storage devices, then data security and protection are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsecurity function complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The storage device autonomously manages security functions including PIN-based authentication, authorization control, and data erasure operations without requiring complex external security systems. The device performs self-verification and self-protection through integrated security modules that automatically execute erasure commands and manage access rights.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Security functions are divided into distinct modules: authentication module for PIN verification, authorization module for access control, and erasure module for data destruction. Each module operates independently with defined responsibilities, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive data erasure mechanisms are implemented, then data protection is improved, but processing time increases

Engineering Contradiction:
Improvedata protectionVSAvoiderasure processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The erasure mechanism dynamically adapts its behavior based on the authentication level and authorization scope. Different erasure strategies are selected automatically: rapid erasure for authenticated users with appropriate permissions, and enhanced verification modes for administrative operations. This dynamic approach optimizes processing time while maintaining security standards.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes operational parameters such as erasure speed, verification depth, and command execution scope based on the authentication state and user authorization level. High-speed erasure modes are activated for authorized operations, while verification and validation parameters are adjusted to match the security requirements of different user levels.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If PIN-based authentication and authorization systems are implemented, then access control is improved, but ease of operation decreases

Engineering Contradiction:
Improveaccess controlVSAvoiduser operation convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

PINs and authorization levels are pre-configured during device setup or factory initialization. Users are provided with their authentication credentials in advance, eliminating the need for complex registration procedures during actual use. The system remembers user identities and permissions across sessions, reducing operational friction.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication and authorization system acts as an intermediary layer between users and data access. Instead of requiring users to directly manage complex security settings, the system automatically handles PIN verification, permission checking, and access control decisions, simplifying user interaction while maintaining robust security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11861194B2Storage device configuration and method managing storage configuration
Publication Date: 2024.01.02 KIOXIA CORP
  • US11861194B2 patent drawing
  • US11861194B2 patent drawing
  • US11861194B2 patent drawing

AI summary

According to one embodiment, a storage device is configured to store unencrypted user data. The user data is erased according to at least one data erasure mechanism. The storage device comprises a receiver configured to receive an inquiry from a host device, and a transmitter configured to transfer response information indicating the at least one data erasure mechanism to the host device.