Storage Device Security Parameter Protection During Partition Resize
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The resizing of partitions in mass storage devices poses risks to the security of encryption and decryption processes, as interrupted reformatting can expose encrypted data in public partitions or store unencrypted data in private partitions, potentially compromising security keys and methods.
Innovation Solution
Generating new security parameters, such as AES encryption/decryption keys, and altering data in affected memory units before updating partition sizes, to ensure that only the old key is exposed in case of data interception and to obscure any retrieved data with the new key, thereby protecting the security process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If partition resizing is performed to increase storage capacity, then storage flexibility is improved, but security of encryption keys and data is compromised
Solution Approach 1:
The system performs preliminary actions by generating new encryption keys and altering data in affected memory units before updating partition sizes. This ensures that if partition resizing is interrupted or compromised, the security parameters remain protected because the old keys are no longer valid and the data has been modified.
Solution Approach 2:
The system applies preliminary anti-action by proactively compromising the old encryption keys through generation of new keys and data alteration before the partition resize operation completes. This pre-emptive measure counteracts potential security breaches that could occur during the partition resizing process.
2Ease of operation
If reformatting is interrupted during partition resizing, then storage operation flexibility is maintained, but encrypted data in public partitions may be exposed
Solution Approach 1:
The system performs preliminary actions by altering data in affected memory units and generating new encryption keys before completing the partition resize operation. This ensures that if the operation is interrupted, the exposed data will be useless for determining security parameters because it has been modified with the new key.
Solution Approach 2:
The system converts the potential harm of data exposure during interrupted reformatting into a benefit by ensuring that any exposed data is encrypted with new keys and has been altered. This transforms what would be a security vulnerability into a protective measure, as the exposed data becomes computationally useless for attacking the encryption system.
3Reliability
If new security parameters are generated and data is altered before updating partition sizes, then security protection is improved, but processing time and complexity increase
Solution Approach 1:
The system merges multiple security operations into a single integrated process. The generation of new encryption keys, the alteration of data in affected memory units, and the update of partition sizes are combined into one atomic operation sequence. This reduces overall complexity by eliminating the need for separate security validation steps while maintaining enhanced security protection.
Solution Approach 2:
The system implements multi-functionality by designing the partition resize operation to simultaneously perform storage reconfiguration and security parameter updates. This universal approach allows a single operation to achieve both storage flexibility and security enhancement without requiring separate dedicated security processes, thereby reducing overall system complexity.
Data Source
AI summary
Security parameters used to encrypt data stored on a storage device may be protected using embodiments of systems and methods described herein. During a resize operation, data stored on a memory unit in the storage device may be altered prior to communicating an updated partition size to a host computer. In some examples, data is altered prior to storing the updated partition sizes in the storage device. In this manner, a host system may not receive the updated partition sizes until after the data is altered. Altering data may avoid exposure encrypted data, information about one or more security parameters used to encrypt data on the memory unit or decrypt data retrieved from the memory unit, or combinations thereof.


