Transient Storage Device Authentication Silo Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The IEEE 1667 standard for transient storage devices (TSDs) lacks guidance on managing multiple authentication silos and configuring authentication hierarchies, leading to complexities in authorization and security when multiple silos are present, especially in varying environmental situations.

Innovation Solution

The implementation of extension fields in manufacturer and provisioning certificates allows for the configuration of multiple authentication silos, enabling logical combinations and hierarchies, optimizing authentication sequences, and enabling or disabling device features within the existing IEEE 1667 and ITU-T X.509 standards, without modifying them.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple authentication silos are implemented in a TSD, then security and authorization control are improved, but device complexity and difficulty of management increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthorization management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication system is segmented into multiple independent authentication silos, each handling a specific authentication method (certificate-based, password-based, biometric). Each silo operates independently with its own authentication logic, allowing the host to selectively combine them according to security requirements without creating a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The authentication configuration is made dynamic through extension fields in certificates that specify logical combinations and ordering of silos. The host can adaptively select which silos to authenticate and in what order based on environmental conditions, user preferences, and security policies, rather than following a fixed authentication sequence.

Inventive Principle:
Principle #15Dynamics

2Ease of manufacture

If the IEEE 1667 standard defines only one type of authentication silo, then implementation is simplified, but adaptability to different authentication methods is reduced

Engineering Contradiction:
Improveimplementation simplicityVSAvoidauthentication method versatility
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The authentication silo structure is designed as a universal framework that can accommodate multiple authentication methods through a common interface. Extension fields in certificates provide a standardized mechanism to specify different authentication types (certificate, password, biometric) and their required logical combinations, allowing the same silo architecture to serve multiple authentication purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses extension fields in X.509 certificates to dynamically specify authentication parameters including silo types, logical combinations (AND/OR relationships), and ordering requirements. By changing these parameter values in the certificate extensions, the system can adapt to different authentication methods and scenarios without modifying the underlying silo architecture.

Inventive Principle:
Principle #35Parameter changes

3Device complexity

If no authentication configuration mechanism is provided in the standard, then the standard remains simple, but flexibility in configuring multiple silos is lost

Engineering Contradiction:
Improvestandard specification complexityVSAvoidauthentication configuration flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

Extension fields in X.509 certificates serve as an intermediary mechanism between the IEEE 1667 authentication silo framework and the need for flexible configuration. These extension fields carry authentication configuration data (silo types, logical combinations, ordering) without requiring modifications to the core IEEE 1667 standard, thus maintaining standard simplicity while enabling configuration flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10366254B2Authorization for transient storage devices with multiple authentication silos
Publication Date: 2019.07.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US10366254B2 patent drawing
  • US10366254B2 patent drawing
  • US10366254B2 patent drawing

AI summary

In a transient storage device (TSD) with multiple authentication silos, a host computing device connected to the TSD is configured by the TSD to discover and act upon various types of authentication information in the silos. One or more logical combinations of authentication silos are switched to the authenticated state to grant access to an associated storage area. A particular ordering of authentication silos may be required to achieve a valid combination of authenticated silos. Ordering may be suggested by configuration information in the TSD. Ordering may also be based upon whether or not user input is required for authenticating a given authentication silo, the environment of use of the TSD, or a hierarchy from most trusted to least trusted authentication silo. With this information, the host proceeds with the most efficient authentication sequence leading to a grant of access to the storage area.