IP Library Granted Patent US 9,871,663
Granted Patent B2
US 9,871,663 · App. 14/668,657 · Granted Jan 16, 2018

Challenge response authentication for self encrypting drives

Inventors: Adrian R. Pearson (Hillsboro, OR); Jason R. Cox (Longmont, CO); James Chu (Hillsboro, OR)
Assignee: INTEL CORPORATION
H04L9/3271G06F12/1408G06F21/52G06F21/6218H04L9/3234H04L9/3257H04L63/061H04L63/0823H04L63/0853G06F2212/1052G06F2221/2139
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,871,663
App. No.
14/668,657
Granted
Jan 16, 2018
Kind
B2
Abstract

Various embodiments are directed to a system for accessing a self-encrypting drive (SED) based on a blind challenge authentication response mechanism (BCRAM). An SED may be authenticated within a system, for example, upon resuming from a sleep state, based on a challenge generated within the SED, signed using a private key by a trusted execution environment (TEE) and authenticated using a corresponding public key within the SED.

Claims (31)

1. An apparatus, comprising:

logic, a portion of which is implemented in hardware, the logic to comprise a blind challenge authentication element (BCAE) component to:

receive a blind challenge response authentication mechanism (BCRAM) request, the BCRAM request to include an indication to authenticate a self-encrypting drive (SED);

generate an arbitrary element;

determine a first challenge authentication element (CAE) based at least in part on the arbitrary element and a public key, the public key corresponding to a private key from a public/private key pair;

determine a padded challenge authentication element (PCAE) based at least in part on the first CAE and a padding constant, the padding constant determined based at least in part on a length of the public key;

generate a BCAE based at least in part on the PCAE and the first CAE and in response to receipt of the BCRAM request;

receive a signed blind challenge authentication element (SBCAE) from a signing entity;

determine an unblind challenge authentication element (UCAE) based on the SBCAE, a second CAE, and the length of the public key, the second CAE based at least in part on the arbitrary element and the length of the public key;

determine authentication credentials to access the SED based at least in part on the UCAE; and

a communications bus communicatively coupled to the logic, the communications bus to communicate the BCAE and SBCAE.

2. The apparatus of claim 1 , the BCAE component to execute in the SED.

3. The apparatus of claim 1 , comprising a decryption component implemented in logic, a portion of which comprises hardware, the decryption component to decrypt a least a portion of the SED based on the authentication credentials.

4. The apparatus of claim 1 , comprising an authentication component implemented in logic, a portion of which comprises hardware, the authentication component to:

determine whether the authentication credentials are valid; and

communicate a request for valid authentication credentials to a host based on the determination that the authentication credentials are not valid.

5. The apparatus of claim 1 , the authentication credentials to include media access keys.

6. At least one non-transitory machine-readable storage medium comprising instructions that when executed by a self-encrypting drive (SED), cause the SED to:

receive a blind challenge response authentication mechanism (BCRAM) request, the BCRAM request to include an indication to authenticate the SED;

generate an arbitrary element;

determine a first challenge authentication element (CAE) based at least in part on the arbitrary element and a public key, the public key corresponding to a private key from a public/private key pair;

determine a padded challenge authentication element (PCAE) based at least in part on the first CAE and a padding constant, the padding constant determined based at least in part on a length of the public key;

generate a blind challenge authentication element (BCAE) based at least in part on the PCAE and the first CAE and in response to receipt of the BCRAM request;

communicate the BCAE to a signing entity;

receive a signed blind challenge authentication element (SBCAE) from the signing entity;

determine an unblind challenge authentication element (UCAE) based on the SBCAE, a second CAE, and the length of the public key, the second CAE based at least in part on the arbitrary element and the length of the public key; and

determine authentication credentials to access the SED based at least in part on the UCAE.

7. The at least one non-transitory machine-readable storage medium of claim 6 , comprising instructions that further cause the SED to decrypt the SED based on the authentication credentials.

8. The at least one non-transitory machine-readable storage medium of claim 6 , comprising instructions that further cause the SED to:

determine whether the authentication credentials are valid; and

communicate a request for valid authentication credentials to a host based on the determination that the authentication credentials are not valid.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 4, 2015
From: PEARSON, ADRIAN R.; COX, JASON R.; CHU, JAMES
To: INTEL CORPORATION
Reel/Frame 035831/0696 →
Continuity (1)
Related Publication 20160285638A1 · Sep 29, 2016