Environment-aware storage drive with expandable security policies

    公开(公告)号:US11144654B2

    公开(公告)日:2021-10-12

    申请号:US16296800

    申请日:2019-03-08

    Abstract: A system includes an environment-aware storage drive comprising one or more storage medium with a location-based service wherein the environment-aware storage drive generates a signal containing information about a location of the storage drive relative to a geo-fenced area and updates a ledger unit of an event happening to the storage drive based on the signal, wherein the event is related to the current environment of the storage drive. The ledger unit keeps track of a number of events and/or data received from the environment-aware storage drive. A policy unit determines an expandable set of security policies for the storage drive triggered by the event and/or data, wherein the security policies specify access restrictions to the environment-aware storage drive based on its current environment. The policy unit transmits and enforces the set of security policies on the environment-aware storage drive to prevent data from being theft from the storage drive.

    DATA STORAGE SYSTEM WITH POWERED MOVE ATTACK PROTECTION

    公开(公告)号:US20210385249A1

    公开(公告)日:2021-12-09

    申请号:US16946088

    申请日:2020-06-05

    Abstract: A data storage system can consist of a network controller connected to a data storage device and a remote host. An attack mitigation strategy may be generated with an attack module connected to the network controller in response to detected data storage conditions in the data storage device. The attack mitigation strategy can be executed with the attack module by sending separate first and second security queries to the data storage device over time. At least a powered move attack can then be identified based on the second security query.

    Removable circuit for unlocking self-encrypting data storage devices

    公开(公告)号:US09768952B1

    公开(公告)日:2017-09-19

    申请号:US14862128

    申请日:2015-09-22

    CPC classification number: H04L9/083 G06F21/575 G06F21/80

    Abstract: Data storage devices (“DSDs”) can be cryptographically locked, and may be unlocked with encryption keys. One or more encryption keys may be stored remotely in a key server, and may be retrieved by a removable circuit that can be coupled to a server, such as a data server, email server, file system server, other server, or other system. The removable circuit can determine which of the DSDs are locked, and may transmit a request to the key server for encryption keys corresponding to the locked DSDs. The removable circuit can unlock the locked DSDs with the encryption keys provided by the key server.

    Data storage system with powered move attack protection

    公开(公告)号:US11611589B2

    公开(公告)日:2023-03-21

    申请号:US16946088

    申请日:2020-06-05

    Abstract: A data storage system can consist of a network controller connected to a data storage device and a remote host. An attack mitigation strategy may be generated with an attack module connected to the network controller in response to detected data storage conditions in the data storage device. The attack mitigation strategy can be executed with the attack module by sending separate first and second security queries to the data storage device over time. At least a powered move attack can then be identified based on the second security query.

    Self-contained key management device

    公开(公告)号:US10678953B1

    公开(公告)日:2020-06-09

    申请号:US15498348

    申请日:2017-04-26

    Abstract: A local key management system can be implemented with a unified extensible firmware interface (“UEFI”) basic input/output system (“BIOS”). The local key management system may be part of a removable data storage device that has a first secure area protected by a cryptographic module (e.g. hardware integrated circuit). The removable data storage device may also have a second secure area that stores a key to unlock a security enabled data storage device. The UEFI BIOS may be implemented to manage unlocking of security enabled data storage devices or data bands. The UEFI BIOS may also load a UEFI registration shell to manage registration of one or more security enabled drives or bands.

    Systems and methods for unlocking self-encrypting data storage devices

    公开(公告)号:US10460110B1

    公开(公告)日:2019-10-29

    申请号:US15436712

    申请日:2017-02-17

    Abstract: Security of computers, data storage devices, and servers can be improved with a multiple key access system. In some embodiments, a local key management device can be a locally (or virtually) located data storage device such as a HDD or SDD. The key management device may be part of a computer or server system and can have a first secure area protected by a cryptographic module (e.g. hardware integrated circuit). The first secure area can store a key to access a second secure area, which may function as a local key management server (LKMS) and store access information to authenticate another data storage device coupled to the computer. For example, the LKMS may store an access key to provide the computer with access to another data storage device.

Patent Agency Ranking