Transient Storage Device Authentication Silo Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The IEEE 1667 standard for transient storage devices (TSDs) lacks guidance on managing multiple authentication silos and configuring authentication hierarchies, leading to complexities in authorization and security when multiple silos are present, especially in varying environmental situations.
Innovation Solution
The implementation of extension fields in manufacturer and provisioning certificates allows for the configuration of multiple authentication silos, enabling logical combinations and hierarchies, optimizing authentication sequences, and enabling or disabling device features within the existing IEEE 1667 and ITU-T X.509 standards, without modifying them.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple authentication silos are implemented in a TSD, then security and authorization control are improved, but device complexity and difficulty of management increase
Solution Approach 1:
The authentication system is segmented into multiple independent authentication silos, each handling a specific authentication method (certificate-based, password-based, biometric). Each silo operates independently with its own authentication logic, allowing the host to selectively combine them according to security requirements without creating a monolithic complex system.
Solution Approach 2:
The authentication configuration is made dynamic through extension fields in certificates that specify logical combinations and ordering of silos. The host can adaptively select which silos to authenticate and in what order based on environmental conditions, user preferences, and security policies, rather than following a fixed authentication sequence.
2Ease of manufacture
If the IEEE 1667 standard defines only one type of authentication silo, then implementation is simplified, but adaptability to different authentication methods is reduced
Solution Approach 1:
The authentication silo structure is designed as a universal framework that can accommodate multiple authentication methods through a common interface. Extension fields in certificates provide a standardized mechanism to specify different authentication types (certificate, password, biometric) and their required logical combinations, allowing the same silo architecture to serve multiple authentication purposes.
Solution Approach 2:
The system uses extension fields in X.509 certificates to dynamically specify authentication parameters including silo types, logical combinations (AND/OR relationships), and ordering requirements. By changing these parameter values in the certificate extensions, the system can adapt to different authentication methods and scenarios without modifying the underlying silo architecture.
3Device complexity
If no authentication configuration mechanism is provided in the standard, then the standard remains simple, but flexibility in configuring multiple silos is lost
Solution Approach 1:
Extension fields in X.509 certificates serve as an intermediary mechanism between the IEEE 1667 authentication silo framework and the need for flexible configuration. These extension fields carry authentication configuration data (silo types, logical combinations, ordering) without requiring modifications to the core IEEE 1667 standard, thus maintaining standard simplicity while enabling configuration flexibility.
Data Source
AI summary
In a transient storage device (TSD) with multiple authentication silos, a host computing device connected to the TSD is configured by the TSD to discover and act upon various types of authentication information in the silos. One or more logical combinations of authentication silos are switched to the authenticated state to grant access to an associated storage area. A particular ordering of authentication silos may be required to achieve a valid combination of authenticated silos. Ordering may be suggested by configuration information in the TSD. Ordering may also be based upon whether or not user input is required for authenticating a given authentication silo, the environment of use of the TSD, or a hierarchy from most trusted to least trusted authentication silo. With this information, the host proceeds with the most efficient authentication sequence leading to a grant of access to the storage area.


