Transient Storage Silo Configuration via IEEE 1667 Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current IEEE 1667 standard for transient storage devices (TSDs) does not allow for changes to silo configuration or availability after the device is released by the manufacturer, limiting user flexibility and security enhancements in the field.
Innovation Solution
A device configuration silo is introduced, which acts as an IEEE 1667-compatible interface, enabling authenticated provisioners to modify silo configurations and availability at runtime, allowing for dynamic configuration of TSDs and controlling data and method sharing across ACTs/LUNs, using secure provisioning mechanisms and secondary authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IEEE 1667 standard is implemented for TSD authentication, then security is improved, but device flexibility and configurability deteriorate
Solution Approach 1:
The patent implements dynamic configuration of silos through a configuration silo that allows runtime modification of silo presence and properties. The system transitions from static manufacturer-defined configurations to dynamic runtime configurations, enabling adaptability while maintaining security through authenticated access controls.
Solution Approach 2:
The patent segments the storage device into multiple addressable command targets (ACTs) with multiple silos, where each silo can be independently configured, enabled, or disabled. This segmentation allows selective activation of functionality while maintaining overall system security through the configuration silo's control mechanisms.
2Reliability
If manufacturer controls silo configuration, then device security is improved, but user adaptability and field configurability worsen
Solution Approach 1:
The configuration silo acts as an intermediary between the manufacturer's initial security settings and user runtime configuration needs. It provides a controlled interface that allows authenticated users to modify silo configurations while maintaining the security framework established by the manufacturer.
Solution Approach 2:
The manufacturer performs preliminary configuration of silos and security settings during device fabrication. The configuration silo then enables users to perform additional configuration actions at runtime based on their specific needs, building upon the manufacturer's preliminary secure setup.
3Adaptability or versatility
If multiple ACTs and silos are supported, then functionality and versatility are improved, but device complexity increases
Solution Approach 1:
The configuration silo provides universal control capabilities for managing multiple ACTs and silos through a unified interface. It can enable/disable silos, modify their properties, and control data sharing across ACTs, providing multi-functional management capability that simplifies the complexity of handling multiple addressable command targets.
4Adaptability or versatility
If runtime configuration changes are enabled, then user flexibility is improved, but security vulnerabilities may increase
Solution Approach 1:
The system performs preliminary authentication and authorization checks before allowing any configuration changes through the configuration silo. By establishing security controls in advance, it prevents unauthorized modifications that could introduce security vulnerabilities, while still allowing legitimate users to make flexible configuration changes.
Data Source
AI summary
A device configuration silo is arranged to be accessed as an IEEE 1667-compatible silo which exposes interfaces to a host application to make changes to the presence of one or more other silos, as well as make changes to silo configurations on a per-silo basis for data and method sharing among silos across the ACTs on a storage device such as a transient storage device. The interfaces exposed by the device configuration silo are arranged to enable an authenticated provisioner, like administrator in a corporate network environment, to perform configuration changes to silos after the storage device is released into the field through a secure provisioning mechanism. In addition, users may make configuration changes to silos at runtime in some usage scenarios, for example to enable discrete portions of functionality on a storage device, by using a secure secondary authentication mechanism that is exposed by the device configuration silo.


