EP4242902A2

Self-encrypting module with embedded wireless user authentication

Abstract

Methods, systems, and computer programs are presented for a self-encrypting device (SED) incorporated into a host system. In one example, the host system includes a memory, a processor, a data channel in communication with the memory and the processor, and the SED. The SED comprises an authentication subsystem, a storage subsystem that stores encrypted data that is encrypted with an encryption key provided by the authentication subsystem, a radio frequency (RF) transceiver, and a data interface in electrical contact with the data channel. The data interface is locked from sending and receiving data until the SED is unlocked by the authentication subsystem with user-authentication information received via the RF transceiver.

EP4242902A2, drawing sheet 1
Sheet 1 of 32

Term

12.9 yearsto projected expiry

Projected expiry 14 August 2039, counted from filing; an application has no term until it is granted.

  1. Priority
  2. Filed
  3. Published
  4. Today
  5. Projected expiry

13 claims: 10 independent, 3 dependent

  1. 1
    A method comprising:providing (2302) a user interface to access a management server that manages access of users to self-encrypting devices, the management server comprising a database storing information about the users and information about the self-encrypting devices;receiving (2304), by the management server, a request of a user to unlock a self-encrypting device to enable a data channel that provides access from a host computer to the self-encrypting device, the self-encrypting device being in wireless communication with a mobile device, wherein the request is received from the mobile device;verifying (2306), by the management server, authentication information of the user received in the request;and sending (2308), by the management server, an unlock command to the mobile device based on the verifying, wherein the unlock command enables the self-encrypting device to unlock the data channel in response to the mobile device forwarding the unlock command to the self-encrypting device via the wireless communication, the data channel providing data access to encrypted storage in the self-encrypting device.
  2. 4
    The method as recited in any one of claims 1 to 3, further comprising:providing, in the user interface, options to configure the self-encrypting devices, the options being to reset, enable, disable, lock, unlock, password recovery, or password change of the self-encrypting device.
  3. 5
    The method as recited in any one of the preceding claims, wherein each drive has a unique hardware identifier stored in the database.
  4. 6
    The method as recited in any one of the preceding claims, further comprising:providing, in the user interface, options to allow access to one or more self-encrypting devices by a given user.
  5. 7
    The method as recited in any one of the preceding claims, further comprising:providing, in the user interface, options to establish geographic boundaries for use of the self-encrypting devices by the user, the geographic boundaries defined for a location of the mobile device.
  6. 8
    The method as recited in any one of the preceding claims, further comprising:providing, in the user interface, options to establish one or more time boundaries for use of the self-encrypting devices by the user.
  7. 9
    The method as recited in any one of the preceding claims, further comprising:providing, in the user interface, options to manage licenses for an account in the management server, the options including determining a maximum number of administrators, a maximum number of self-encrypting devices, and a maximum number of users.
  8. 10
    The method as recited in any one of the preceding claims, further comprising:providing, in the user interface, options to view self-encrypting device activity including date of provisioning, user that provisioned, time of last access, user in last access, and geographic location of last access.
  9. 11
    The method as recited in any one of the preceding claims, further comprising:receiving, via the user interface, a request to recover a user password for the user for a given self-encrypting device;authenticating, by the management server, the user for access to the given self-encrypting device;and providing the user password to the user based on the authenticating, the user password being retrieved from the database.
  10. 12
    A management server (604; 2400) comprising:a memory (2404, 2406, 2416) comprising instructions (2424);a database (642) storing information about users and information about self-encrypting devices;and one or more computer processors (2402), wherein the instructions (2424), when executed by the one or more computer processors, cause the management server (2400) to perform the method of any one of claims 1 to 11.