Wireless Security Protocol for Data Storage Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Bluetooth standards lack robust security measures, particularly in high-security applications, where unauthorized access to data storage devices via wireless connections poses risks, and there is a need to prevent sharing of private information during the authentication process.
Innovation Solution
A security protocol utilizing out-of-band communication for identity key exchange between a server and client, where a message authentication code (MAC) is calculated using the identity key and a random value, allowing the client to authenticate the server without sharing private information, and subsequently securing the communication channel using a cryptographic key derived from this process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If Bluetooth pairing is used for wireless connection, then device connectivity is simplified and ease of operation is improved, but security is compromised and private information may be exposed to unauthorized devices
Solution Approach 1:
The authentication process is divided into two independent stages: (1) out-of-band identity key exchange through proximity-based communication, and (2) cryptographic authentication using message authentication codes. This segmentation allows simple device pairing while maintaining security through separate authentication mechanisms.
Solution Approach 2:
An identity key serves as an intermediary element that enables secure authentication without directly exposing private information. The identity key is exchanged out-of-band and used to generate message authentication codes, acting as a mediator between the simplicity of Bluetooth pairing and the security requirements of encrypted communication.
2Reliability
If private information is shared during pairing, then authentication can be performed, but privacy is compromised and unauthorized access becomes possible
Solution Approach 1:
The identity key is exchanged preliminarily through out-of-band communication before the main authentication process. This preliminary action establishes a secure foundation that enables subsequent authentication without requiring private information to be shared over the potentially insecure wireless channel.
Solution Approach 2:
The critical security element (identity key) is extracted from the main authentication protocol and transferred through a separate out-of-band channel. This extraction prevents the identity key from being exposed during the Bluetooth pairing process, maintaining privacy while enabling authentication.
3Ease of operation
If traditional authentication protocols are used, then connection establishment is straightforward, but vulnerability to malicious devices increases and security is weakened
Solution Approach 1:
The system performs preliminary anti-action by validating message authentication codes generated from out-of-band exchanged identity keys before establishing the wireless connection. This preliminary validation prevents malicious devices from successfully impersonating authorized devices, as they cannot generate valid MACs without the correct identity key.
Solution Approach 2:
The authentication protocol incorporates feedback mechanisms where the client device verifies the server's message authentication code and can reject connections from unauthorized devices. This feedback loop ensures that only devices with valid identity keys can establish connections, providing resistance against malicious devices while maintaining straightforward connection establishment for authorized devices.
Data Source
AI summary
This disclosure relates to a data storage device. A data port transmits data between a host computer system and the data storage device over a data channel. The device repeatedly broadcasts advertising packets over a wireless communication channel different from the data channel. Each advertising packet comprises a random value and a message authentication code calculated based on the random value and an identity key. The identity key is readable by a device to be connected and in proximity of the data storage device out of band of the data channel and the communication channel. The identity key enables the device to be connected to verify the message authentication code based on the random value and the identity key to thereby authenticate the data storage device.


