Network Storage Trusted Device Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network storage devices in shared environments, such as NAS and SAN, lack effective security features to protect sensitive data from unauthorized access and tampering, particularly in environments where data is shared across multiple organizations.

Innovation Solution

Incorporating a trusted device, such as a TPM, into the storage device to store data with a coded identifier associated with authorized users, enabling strong authentication and ensuring only authorized individuals can access the data, using cryptographic processes and tamper-resistant modules to secure data access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is stored in a shared network storage device, then storage capacity and sharing benefits are improved, but security and unauthorized access risks worsen

Engineering Contradiction:
Improvestorage sharing capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The storage device is segmented into multiple independently secured storage locations, each protected by its own authentication mechanism. The trusted device divides access control into discrete authenticated sessions, where each user receives temporary access credentials that are valid only for specific operations and time periods, preventing unauthorized access while maintaining shared access capability

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted device acts as an intermediary between users and the storage locations. This intermediary component verifies user credentials, manages authentication credentials, and controls access to stored data. The trusted device mediates all access requests, ensuring that only authenticated users can access their authorized data while preventing direct unauthorized access to the storage medium

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If application software security features are used in LAN, then data access control is improved, but vulnerability to network attacks worsens

Engineering Contradiction:
Improvedata access controlVSAvoidsoftware security reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces software-based security mechanisms with hardware-based security features embodied in the trusted device. The trusted device contains dedicated security circuits, cryptographic processors, and authentication logic that are physically embedded in the storage device, making them resistant to software attacks, viruses, and unauthorized modification while providing robust access control

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

Security functionality is extracted from the main storage device into a separate, dedicated trusted device component. This extraction isolates critical security functions from the general-purpose storage controller and software, creating a specialized security subsystem that can operate independently and resist attacks targeting the main system

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If physical security measures are shared among multiple organizations, then security reliability is improved, but cost and complexity worsen

Engineering Contradiction:
Improvephysical security reliabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted device implements universal security functions that serve multiple organizations and storage locations simultaneously. A single trusted device can manage authentication for multiple users from different organizations, control access to multiple storage locations, and provide cryptographic services for various data types, eliminating the need for separate security systems for each organization

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7596702B2Network storage devices
Publication Date: 2009.09.29 HEWLETT PACKARD ENTERPRISE DEV LP
  • US7596702B2 patent drawing
  • US7596702B2 patent drawing
  • US7596702B2 patent drawing

AI summary

A storage box includes bulk non-volatile memory storage locations, an input/output unit for connection to a network, and a controller for controlling reading and writing of data from and to the storage locations. A trusted device is physically associated with/incorporated into the controller. At least one of the controller and the trusted device is configured such that in writing data to the memory storage locations, the data are stored in conjunction with a coded identifier which is associated with a person or organization that is authorized to read the data.