Storage Device PPA Mechanism for Hijacking Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Secure storage devices, such as HDDs and SSDs, are vulnerable to hijacking when connected to networks, as remote intruders can exploit default credentials and execute sensitive commands, leading to data loss and unauthorized access, especially if user education lags behind technological advancements.

Innovation Solution

Implementing a Proof of Physical Access (PPA) mechanism that requires direct user intervention to execute protected commands like changing credentials, formatting, or sanitizing the drive, using methods like magnetically operated reed switches, radio receivers, or light sensors to verify physical possession before allowing such operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If secure storage devices are connected to networks with default credentials, then ease of operation is improved, but vulnerability to hijacking and unauthorized access increases

Engineering Contradiction:
Improveease of operationVSAvoidvulnerability to hijacking
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication by requiring proof of physical access (PPA) before allowing execution of protected commands. The PPA mechanism is activated in advance and must be satisfied before sensitive operations can proceed, preventing remote intruders from executing commands without physical presence.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary PPA verification layer between the host and storage device communication. This intermediary mechanism (using sensors like reed switches, radio receivers, or light sensors) mediates command execution by verifying physical access, thereby blocking unauthorized remote access while maintaining legitimate local access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If Proof of Physical Access mechanism is implemented, then security against hijacking is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against hijackingVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The PPA verification functionality is extracted as a separate, dedicated mechanism within the storage device. By isolating the PPA verification logic and sensors as distinct components, the system adds security functionality without significantly complicating the core storage operations, allowing independent implementation and maintenance of the security feature.

Inventive Principle:
Principle #2Taking out (Extraction)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Prevents remote intruders from executing sensitive commands without physical access, ensuring user control over secure storage devices and protecting against hijacking, thereby safeguarding data integrity and user ownership.

Implementation Method 1

using methods like magnetically operated reed switches

Methodology Applied
Scientific EffectMagnetic field detection: Magnetic Field

Implementation Method 2

radio receivers

Methodology Applied
Scientific EffectRadio frequency detection: Radar

Implementation Method 3

light sensors

Methodology Applied
Scientific EffectLight detection: Light

Data Source

PatentUS9753869B2Techniques for secure storage hijacking protection
Publication Date: 2017.09.05 SEAGATE TECH LLC
  • US9753869B2 patent drawing
  • US9753869B2 patent drawing
  • US9753869B2 patent drawing

AI summary

Various embodiments of the present disclosure are directed to a storage device having a non-volatile memory, a Proof of Physical Access (PPA) mechanism and a controller circuit. The PPA mechanism generates a PPA value responsive to a direct physical user interaction with the storage device by a user. In response to receipt of a storage command from a host, the controller circuit executes the received storage command responsive to the storage command being determined to be a protected command and responsive to detection of the PPA value during a predetermined window of time. The controller circuit does not execute the received storage command responsive to the storage command being determined to be a protected command and responsive to an absence of the PPA value during the predetermined window of time. The protected command is a command that changes access to data stored in the non-volatile memory.