Storage Device Security Parameter Protection During Partition Resize

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The resizing of partitions in mass storage devices poses risks to the security of encryption and decryption processes, as interrupted reformatting can expose encrypted data in public partitions or store unencrypted data in private partitions, potentially compromising security keys and methods.

Innovation Solution

Generating new security parameters, such as AES encryption/decryption keys, and altering data in affected memory units before updating partition sizes, to ensure that only the old key is exposed in case of data interception and to obscure any retrieved data with the new key, thereby protecting the security process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If partition resizing is performed to increase storage capacity, then storage flexibility is improved, but security of encryption keys and data is compromised

Engineering Contradiction:
Improvestorage flexibilityVSAvoidsecurity of encryption keys
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by generating new encryption keys and altering data in affected memory units before updating partition sizes. This ensures that if partition resizing is interrupted or compromised, the security parameters remain protected because the old keys are no longer valid and the data has been modified.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies preliminary anti-action by proactively compromising the old encryption keys through generation of new keys and data alteration before the partition resize operation completes. This pre-emptive measure counteracts potential security breaches that could occur during the partition resizing process.

Inventive Principle:
Principle #9Preliminary anti-action

2Ease of operation

If reformatting is interrupted during partition resizing, then storage operation flexibility is maintained, but encrypted data in public partitions may be exposed

Engineering Contradiction:
Improveoperation flexibilityVSAvoiddata exposure risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by altering data in affected memory units and generating new encryption keys before completing the partition resize operation. This ensures that if the operation is interrupted, the exposed data will be useless for determining security parameters because it has been modified with the new key.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system converts the potential harm of data exposure during interrupted reformatting into a benefit by ensuring that any exposed data is encrypted with new keys and has been altered. This transforms what would be a security vulnerability into a protective measure, as the exposed data becomes computationally useless for attacking the encryption system.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If new security parameters are generated and data is altered before updating partition sizes, then security protection is improved, but processing time and complexity increase

Engineering Contradiction:
Improvesecurity protectionVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges multiple security operations into a single integrated process. The generation of new encryption keys, the alteration of data in affected memory units, and the update of partition sizes are combined into one atomic operation sequence. This reduces overall complexity by eliminating the need for separate security validation steps while maintaining enhanced security protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements multi-functionality by designing the partition resize operation to simultaneously perform storage reconfiguration and security parameter updates. This universal approach allows a single operation to achieve both storage flexibility and security enhancement without requiring separate dedicated security processes, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8949626B2Protection of security parameters in storage devices
Publication Date: 2015.02.03 MICRON TECHNOLOGY INC
  • US8949626B2 patent drawing
  • US8949626B2 patent drawing
  • US8949626B2 patent drawing

AI summary

Security parameters used to encrypt data stored on a storage device may be protected using embodiments of systems and methods described herein. During a resize operation, data stored on a memory unit in the storage device may be altered prior to communicating an updated partition size to a host computer. In some examples, data is altered prior to storing the updated partition sizes in the storage device. In this manner, a host system may not receive the updated partition sizes until after the data is altered. Altering data may avoid exposure encrypted data, information about one or more security parameters used to encrypt data on the memory unit or decrypt data retrieved from the memory unit, or combinations thereof.