Secure Read-Write Storage Device with Data Corruption Sanctions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing read-write storage (RWS) devices in secure systems are vulnerable to piracy attacks such as code extraction, execution of malicious code, unauthorized reading, and unauthorized writing, as most solutions treat the RWS device as an atomic module and assume intermediate results cannot be read or altered.

Innovation Solution

The RWS device employs a controller with a sanction mechanism that includes disguising or corrupting data, such as control data and keys, and can reset or turn off parts of the device, entering an infinite loop, or corrupting data stored in the bit bucket, with authorized servers able to reverse the corruption, using encryption and authentication mechanisms to secure data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the RWS device is treated as an atomic module with assumed immutability of intermediate results, then the device structure remains simple, but the device becomes vulnerable to piracy attacks that read or alter intermediate results

Engineering Contradiction:
Improvesecurity against piracy attacksVSAvoiddevice structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the RWS device into distinct functional segments: a controller and a bit bucket (storage array). This segmentation allows independent protection of each component - the controller executes security policies while the bit bucket stores data, enabling the system to detect and respond to piracy attacks without requiring the entire device to be monolithic and complex.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary security measures by establishing authentication mechanisms and sanctions before piracy attacks can occur. The controller pre-configures authentication protocols to verify data integrity and pre-defines sanction policies (such as data corruption or erasure) that will be automatically executed if unauthorized access is detected, preventing attacks before they can compromise the system.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security mechanisms are implemented to prevent code extraction and unauthorized access, then the security level improves, but the device complexity increases

Engineering Contradiction:
Improvedata integrity and access controlVSAvoidsecurity mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts critical security functions from the main storage operations and places them in the controller. Authentication, authorization, and sanction execution are separated as distinct functional modules, allowing the storage array to focus on data operations while the controller handles security policies. This extraction reduces overall system complexity by modularizing security mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The controller implements self-service security mechanisms by autonomously executing authentication protocols and sanction policies without external intervention. When unauthorized access is detected, the controller automatically applies predefined sanctions (such as corrupting or erasing data) and maintains security state, eliminating the need for complex external security management systems.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If sanctions such as data corruption and device reset are implemented to respond to piracy attacks, then the security response capability improves, but the ease of operation deteriorates

Engineering Contradiction:
Improveresistance to piracy attacksVSAvoiddevice usability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The patent converts the harmful effect of piracy attacks into beneficial security reinforcement. When unauthorized access is detected, the controller executes sanctions that corrupt or erase the attacker's data, transforming the attack attempt into an opportunity to strengthen security. The same mechanism that responds to attacks also prevents legitimate data loss by requiring authentication for all operations.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent implements feedback mechanisms where the controller continuously monitors access patterns and compares them against authorized policies. When deviations indicating piracy attacks are detected, the system provides feedback through automatic sanction execution. This closed-loop feedback ensures that security responses are adaptive and automatically adjust to current threat levels without affecting normal operational usability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8751821B2Secure read-write storage device
Publication Date: 2014.06.10 CISCO TECHNOLOGY INC
  • US8751821B2 patent drawing
  • US8751821B2 patent drawing
  • US8751821B2 patent drawing

AI summary

A method and system for securing a read write storage (RWS) device, the method comprising, providing the RWS device, the RWS device comprising a controller comprising a processor and a bit bucket storing data, and employing the controller to corrupt at least a portion of the data.