Storage Device Partition Protection via Nonstandard File System Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current partition protection schemes for storage devices, such as HPA and Type 12 partitions, face issues with compatibility, data integrity, and security, leading to instability and increased maintenance costs, as well as weakened security when user-accessible file systems are mounted.
Innovation Solution
The proposed solution involves dividing the protected partition into an application data area and a system data area, with system data stored in a customized nonstandard file system format, and utilizing a partition boot record to manage and secure system data, ensuring it remains intact even when accessed by users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HPA partition protection scheme is used, then partition security is improved, but compatibility and stability deteriorate
Solution Approach 1:
The protected partition is segmented into two distinct areas: a system data area with nonstandard file system for protected system files, and an application data area with standard file system for user applications. This segmentation allows different security levels and file system types to coexist, improving both security and compatibility.
Solution Approach 2:
Different file system types are applied to different regions of the protected partition. The system data area uses a nonstandard file system for security, while the application data area uses a standard file system for compatibility. This local differentiation resolves the contradiction between security and adaptability.
2Reliability
If HPA partition protection scheme is used, then partition security is improved, but data parsing and maintenance difficulty increases
Solution Approach 1:
By separating system data and application data into different areas with different file systems, the patent enables targeted parsing and maintenance. Standard file system tools can work on the application data area without affecting the protected system data area, easing maintenance while preserving security.
Solution Approach 2:
The partition boot record (PA_MBR) acts as an intermediary structure that manages both the standard and nonstandard file system areas. It provides a unified interface for parsing and maintenance operations, allowing tools to access and manage protected data without compromising security.
3Reliability
If Type 12 partition protection scheme is used, then partition security is improved, but security weakens when mounted as disk label
Solution Approach 1:
The patent applies different file system types to different regions: nonstandard file system for system data that requires strong protection, and standard file system for application data that needs user accessibility. This local differentiation ensures that even when mounted, only the application data area is vulnerable, while the system data area remains protected.
Solution Approach 2:
By segmenting the partition into protected system data area and accessible application data area, the patent limits the scope of vulnerability. When the partition is mounted as a disk label, users can only access the standard file system portion, while the nonstandard file system portion remains protected from reading and writing operations.
4Reliability
If protected partition size is hidden from users, then partition security is improved, but information accuracy deteriorates
Solution Approach 1:
The patent segments the protected partition into two areas with different security levels. The MBR records the total size (both system and application data areas), making the full storage capacity visible to users. However, the system data area remains protected through its nonstandard file system, resolving the contradiction between visibility and security.
Data Source
AI summary
The present invention provides a storage device and a method for protecting its protected partition in which the storage device comprises a master boot record unit and a protected partition, the protected partition comprises an application data area and a system data area for storing application data and system data to be provided to a user, respectively, and the system data area is in a customized data format of nonstandard file system. With the storage device and the method for protecting its protected partition, security of system data in the protected partition of the storage device is enhanced.


