Tape Cartridge MAM Encrypted Key Cloud Retrieval
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing threat of data breaches and unauthorized access to encrypted data stored on tape cartridges and other mobile media necessitates a secure and cost-effective method for managing encrypted data keys, as maintaining local private keys is expensive and vulnerable to attacks.
Innovation Solution
Implementing a system where an encrypted data key is stored on a tape cartridge's medium auxiliary memory device, allowing it to be used to retrieve a corresponding data key from a public cloud server for decryption, thereby ensuring secure and cost-effective encryption and decryption of user data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data keys are stored locally on tape cartridges, then decryption capability is maintained, but security vulnerability increases due to persistent local storage
Solution Approach 1:
The patent extracts the data key from local storage on the tape cartridge and relocates it to a remote cloud-based key management service. The encrypted data key remains on the cartridge while the actual data key is stored remotely, separating the decryption capability from the physical media and eliminating the security vulnerability of persistent local key storage.
Solution Approach 2:
The patent introduces a cloud-based key management service as an intermediary between the encrypted data on the tape cartridge and the decryption process. This mediator holds the actual data key securely and provides it temporarily for decryption operations, enabling reliable decryption while maintaining security through centralized, controlled access rather than local persistence.
2Object-affected harmful factors
If data keys are stored in a public cloud service, then security is improved by eliminating local key persistence, but cost increases due to cloud service dependency
Solution Approach 1:
The patent creates a cryptographic copy relationship where the encrypted data key on the tape cartridge serves as a secure reference to the actual data key stored in the cloud. This copying mechanism allows the system to leverage cloud-based security improvements while minimizing costs by using efficient cryptographic operations rather than expensive redundant storage or frequent cloud access operations.
3Speed
If encrypted data keys are stored on tape cartridges, then data access speed is improved, but unauthorized access risk increases
Solution Approach 1:
The patent segments the key management functionality by separating the encrypted data key (stored locally on the tape cartridge for fast access) from the actual data key (stored securely in the cloud). This segmentation enables rapid data access by keeping the encrypted key locally while mitigating unauthorized access risk by requiring cloud-based authentication and controlled key release for actual decryption operations.
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
This approach significantly reduces costs by leveraging public cloud services for key management, providing robust security by ensuring that data keys are not persistently stored locally, thus minimizing the risk of unauthorized access and maintaining data integrity.
Implementation Method 1
a transceiver; a microprocessor; and an encrypted data key retained to the non-transient solid state memory device
Data Source
AI summary
A method for securing user data that is stored to a tape cartridge having a medium auxiliary memory (MAM) is described. When user data is sent to a tape library from a client, the tape library sends a request to a cloud based key management service for a data key to encrypt the user data and an encrypted data key that corresponds to the data key. The data key is used to encrypt the user data which is then stored to the tape cartridge and the encrypted data key is stored to the MAM. Upon decrypting the encrypted user data, the encrypted data key is extracted from the MAM and sent to the cloud based key management service where it is used to produce the data key from the cloud based key management service which is then sent to the tape library. When the tape library is in possession of the data key, the encrypted data in the tape cartridge can then be decrypted and sent to a requester of the user data.


