Storage Drive Encryption Key Management via External Managers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for encrypting data in removable media cartridges are costly and complex, and implementing encryption engines in host systems or storage drives creates computational burdens and challenges in managing encryption keys for different cartridges.

Innovation Solution

A storage drive is configured to communicate with encryption and key managers to determine encryption status and obtain necessary keys for encrypting data, using symmetric or asymmetric encryption algorithms, and managing keys through key management code and encryption engines integrated within the storage drive.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption engine is implemented in host system, then data encryption capability is provided, but computational burden on host system increases

Engineering Contradiction:
Improvedata encryption capabilityVSAvoidcomputational burden on host system
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The encryption engine is extracted from the host system and relocated to the storage drive. The storage drive now contains the encryption engine and can autonomously perform encryption and decryption operations on data stored on removable media cartridges, eliminating the computational burden from the host system while maintaining data encryption capability.

Inventive Principle:
Principle #2Taking out (Extraction)

2Use of energy by moving object

If encryption engine is implemented in storage drive, then computational burden on host system is reduced, but challenges in managing encryption keys for different cartridges arise

Engineering Contradiction:
Improvecomputational burden on host systemVSAvoidencryption key management complexity
Core Design Contradiction:
Use of energy by moving objectVSDevice complexity

Solution Approach 1:

An encryption manager is introduced as an intermediary component that communicates with the storage drive. The encryption manager handles the complexity of key management for different removable media cartridges, while the storage drive focuses on execution. This separation allows the storage drive to have reduced complexity while still supporting encryption for multiple cartridges through centralized key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If bump in the wire encryption device is used, then data encryption is achieved, but solution becomes costly and complex

Engineering Contradiction:
Improvedata encryptionVSAvoidsolution complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption functionality is merged directly into the storage drive, combining the storage and encryption functions in a single device. This eliminates the need for separate encryption devices in the data path, reducing overall system complexity and cost while maintaining data encryption capability. The storage drive becomes a multi-functional device that handles both storage and security operations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7877603B2Configuring a storage drive to communicate with encryption and key managers
Publication Date: 2011.01.25 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US7877603B2 patent drawing
  • US7877603B2 patent drawing
  • US7877603B2 patent drawing

AI summary

Provided are a method, system, and article of manufacture for configuring a storage drive to communicate with encryption and key managers. A storage drive receives a request to access a coupled removable storage media for drive operations. The storage drive obtains encryption status for the coupled removable storage media from an encryption manager. The storage drive determines from the obtained encryption status whether to encrypt the coupled removable storage media to access. The storage drive obtains at least one key from a key manager in response to determining to encrypt with respect to the coupled removable storage media. The storage drive performs data operations using the at least one key to encrypt data.