Self-Encrypting Storage Key Management via Segmented Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for unlocking self-encrypting data storage devices lack efficient methods for secure key management and communication, particularly when connecting and disconnecting removable data storage devices from servers, which can lead to unauthorized access and data security breaches.
Innovation Solution
A key management system stored on a removable data storage device that connects to a server, utilizing a hardware encryption circuit to access secure storage areas, retrieve access keys, and secure communication between devices, ensuring secure unlocking and communication of self-encrypting data storage devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a key management system is implemented to securely manage encryption keys, then data security is improved, but system complexity increases
Solution Approach 1:
The system divides key management into separate secure modules: a key management system stored on the removable device, hardware encryption circuits on both the removable device and server, and secure storage areas. This segmentation isolates key handling functions from general data processing, improving security while organizing complexity into manageable, specialized components.
Solution Approach 2:
The key management system acts as an intermediary between the removable data storage device and the server. It mediates authentication and key exchange processes, enabling secure communication without requiring the server to directly handle sensitive key material, thus improving security while simplifying the server's role.
2Reliability
If hardware encryption circuits are used to protect secure storage areas, then access security is improved, but device complexity and cost increase
Solution Approach 1:
The patent combines hardware encryption circuits with the removable data storage device and server infrastructure. By merging encryption capabilities directly into the storage device, the system achieves strong access security without requiring separate hardware security modules, reducing overall system complexity while maintaining high security standards.
3Reliability
If communication keys are used to secure communication between devices, then communication security is improved, but key management complexity increases
Solution Approach 1:
The key management system performs multiple functions: storing encryption keys, generating communication keys, authenticating devices, and managing secure access to storage areas. By creating a universal key management system that handles all cryptographic operations in one place, the system improves communication security while reducing the need for multiple separate key management mechanisms.
Data Source
AI summary
Security of computers, data storage devices, and servers can be improved with a multiple key access system. In some embodiments, a local key management device can be a locally (or virtually) located data storage device such as a HDD or SDD. The key management device may be part of a computer or server system and can have a first secure area protected by a cryptographic module (e.g. hardware integrated circuit). The first secure area can store a key to access a second secure area, which may function as a local key management server (LKMS) and store access information to securely communicate with and unlock another data storage device coupled to the computer. For example, the LKMS may store an access key to provide the computer with access to another data storage device. Communications between the LKMS and the other data storage device may be encrypted using a communication key.


