Portable Storage Device Self-Authentication Mode Conversion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Portable secure storage devices lack secure self-authentication and mode conversion capabilities without host involvement, leading to potential unauthorized access and configuration changes.
Innovation Solution
A portable secure storage device with an internal controller that can self-authenticate, determine modes, and convert to a renewed mode securely without host communication, using a physical input device for access code entry and mode management, with exclusive and non-exclusive modes to control access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If portable secure storage devices require host software for authentication and mode conversion, then host control and coordination are improved, but security vulnerabilities and unauthorized access risks increase
Solution Approach 1:
The storage device performs self-authentication using an access code entered through its own input device, and executes self-mode conversion between exclusive and non-exclusive modes without requiring host software intervention. The controller internally verifies the access code and autonomously transitions modes, making the device self-sufficient for security-critical operations.
Solution Approach 2:
The device separates authentication and mode conversion functions into independent internal operations that do not require host involvement. The input device, controller, and mode management system are segmented to operate autonomously, with the controller handling authentication separately from host communication functions.
2Ease of operation
If the device allows mode conversion without privileged access code verification, then ease of operation is improved, but security and unauthorized configuration changes worsen
Solution Approach 1:
The device dynamically adjusts its operational mode between exclusive and non-exclusive states based on authentication status. When a privileged access code is verified, the device transitions to non-exclusive mode allowing broader access; without verification, it remains in exclusive mode with restricted access, creating dynamic security adaptation.
Solution Approach 2:
The device changes its access control parameters by transitioning between exclusive and non-exclusive modes. The exclusive mode enforces strict access control requiring privileged codes, while non-exclusive mode relaxes these constraints, allowing the system to adapt security parameters based on authentication events.
3Productivity
If host software is required for authentication and mode management, then coordination and control are improved, but device performance and security are reduced due to external dependencies
Solution Approach 1:
The patent extracts authentication and mode conversion functions from the host software environment and relocates them to the storage device itself. By taking out these critical security functions from the host dependency, the device eliminates the security vulnerabilities and performance overhead associated with external software while maintaining proper control and coordination.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Highly secure portable storage device includes a physical input device, a memory and a controller, all of which reside within or on the device itself. The controller may determine whether the device is in an exclusive or nonexclusive mode, whether the device is in a privileged mode, a locked mode or a protected mode, and whether a request is made to self-transform to a renewed mode. When the request is made and the device is in the nonexclusive mode, the device self-transforms to the renewed mode without requiring communication with the host and without requiring access code verification. When the request is made and the device is in the exclusive mode, the device self-transforms to the renewed mode only when a privileged security access code is verified. Transforming to a renewed mode sets all access codes to null and sets a new encryption key. Other methods and implementations are described.