Unlocking a Data Storage Device Using a Web Application
A data storage device (DSD) includes a storage medium and a processor. The storage medium includes a protected partition, inaccessible through mass storage device protocols, that stores program code to: emulate a webserver and to provide a first web application to a browser of the host device to configure the DSD. The storage medium includes a secured partition to store user data and an unsecured partition readable by the host device. The unsecured partition stores a second web application for the browser to unlock the DSD and to enable access to the secured partition with a mass storage device protocol.
1 . A data storage device, comprising:
a storage medium comprising:
a protected partition inaccessible through a mass storage device protocol, wherein the protected partition stores program code, when executed, to emulate at least a webserver configured to provide a first web application to a browser of a host device to configure the data storage device;
a secured partition configured to store user data under the mass storage device protocol, and
an unsecured partition readable by the host device, wherein the unsecured partition stores at least a second web application, wherein the second web application is different from the first web application and is executable through the browser of the host device to unlock the data storage device;
a communication interface configured to communicate with the host device; and
at least one processor configured, individually or in combination, to:
communicatively couple with the host device, via at least one control communication channel, wherein the at least one processor is configured to emulate a network adapter to the host device, wherein the at least one control communication channel is enabled by an Ethernet over USB (Universal Serial Bus) protocol driver, wherein the second web application is configured to specify an IP (Internet Protocol) address associated with the data storage device to unlock the data storage device via the at least one control communication channel;
receive, via the at least one control communication channel, authentication data to unlock the data storage device, wherein the authentication data is received from the second web application instantiated at the browser of the host device;
verify that the received authentication data corresponds to a record in an authentication data set configured by the first web application; and
in response to verifying the received authentication data, unlock the data storage device to enable access between the host device and the secured partition via a data communication channel, wherein the data communication channel is enabled by a USB mass storage driver.
2 . The data storage device according to claim 1 , wherein specifying the IP address associated with the data storage device by the second web application comprises:
retrieving, by the second web application, a predefined IP address corresponding to the webserver of the data storage device,
wherein the predefined IP address is stored in the second web application or stored in a second web application data structure associated with the second web application,
wherein the second web application data structure is stored in the secured partition.
3 . The data storage device according to claim 2 , wherein retrieving the predefined IP address corresponding to the webserver of the data storage device comprises: receiving, by a TCP/IP (Transmission Control Protocol/Internet Protocol) stack of the host device, the predefined IP address from the second web application.
4 . The data storage device according to claim 1 , wherein the first web application is configured to configure the data storage device via the at least one control communication channel.
5 . The data storage device according to claim 4 , wherein the first web application is configured to configure the data storage device via a first control communication channel of the at least one control communication channel, and wherein the data storage device is configured to receive the authentication data to unlock the data storage device via a second control communication channel of the at least one control communication channel.
6 . The data storage device according to claim 5 , wherein the first control communication channel is different from the second control communication channel.
7 . The data storage device according to claim 5 , wherein the first control communication channel is the same as the second control communication channel.
8 . The data storage device according to claim 1 , wherein the at least one processor is further configured to receive, via the at least one control communication channel, an unlock request from the host device using the second web application, wherein in response to receiving the unlock request, the second web application initiates a first interface in the browser of the host device, wherein the first interface is configured to receive the authentication data to unlock the data storage device.
9 . The data storage device according to claim 8 , wherein the second web application is configured to automatically initiate the first interface in the browser of the host device in response to the at least one control communication channel being established.
10 . The data storage device according to claim 8 , wherein the Ethernet over USB protocol driver is a CDC-NCM (Communication Device Class Network Control Model) driver, wherein the unlock request from the host device and the authentication data are received from the CDC-NCM driver over the at least one control communication channel.
11 . The data storage device according to claim 1 , wherein the first web application configuring the data storage device comprises any one or more of:
sending the first web application from the protected partition to the host device, wherein the host device instantiates the first web application on the browser of the host device;
configuring data related to access control including storing the authentication data set in the protected partition;
encrypting the data related to access control; and/or initializing the second web application including any one or more of:
configuring any one or more of: the first interface, a second interface of the second web application configured to receive the unlock request from the host device, and/or a third interface of the second web application configured to present whether the data storage device is unlocked or not;
linking an authentication module of the at least one processor of the data storage device to the second web application; and/or
enabling encryption to the unlock request and/or the authentication data.
12 . The data storage device according to claim 1 , wherein the second web application stored in the secured partition is read-only and/or write protected.
13 . The data storage device according to claim 1 , wherein the communication interface includes a USB bridge, and wherein the at least one control communication channel and the data communication channel are respective logical pipes through a USB interface between the host device and the data storage device.
14 . The data storage device according to claim 1 , wherein the first web application and/or the second web application comprise at least one or more of:
Hypertext Markup Language (HTML);
Cascading Style Sheets; and
JavaScript.
15 . A method for unlocking a data storage device using a host device, wherein the data storage device comprises a storage medium comprising: a protected partition inaccessible through a mass storage device protocol, wherein the protected partition stores program code that, when executed, emulates at least a webserver configured to provide a first web application to a browser of a host device to configure the data storage device; and a secured partition configured to store user data under the mass storage device protocol, wherein the secured partition stores at least a second web application, wherein the second web application is different from the first web application and is executable through the browser of the host device to unlock the data storage device; wherein the data storage device further comprises a communication interface configured to communicate with a host device and at least one processor; the method comprising:
communicatively coupling with the host device, via at least one control communication channel, wherein the at least one processor is configured to emulate a network adapter to the host device, wherein the at least one control communication channel is enabled by an Ethernet over USB (Universal Serial Bus) protocol driver, wherein the second web application is configured to specify an IP (Internet Protocol) address associated with the data storage device for unlocking the data storage device via the at least one control communication channel;
receiving, via the at least one control communication channel, authentication data to unlock the data storage device, wherein the authentication data is received from the second web application instantiated at the browser of the host device;
verifying that the received authentication data corresponds to a record in an authentication data set configured by the first web application; and
in response to verifying the received authentication data, unlocking the data storage device to enable access between the host device and the secured partition via a data communication channel, wherein the data communication channel is enabled by a USB mass storage driver.
16 . The method according to claim 15 , wherein specifying the IP address associated with the data storage device by the second web application comprises retrieving a predefined IP address corresponding to the webserver of the data storage device, wherein the predefined IP address is stored in the second web application.
17 . The method according to claim 16 , wherein retrieving the predefined IP address corresponding to the webserver of the data storage device comprises receiving, by a TCP/IP (Transmission Control Protocol/Internet Protocol) stack of the host device, the predefined IP address from the second web application.
18 . The method according to claim 13 , wherein the first web application is configured to configure the data storage device via a first control communication channel of the at least one control communication channel, wherein the data storage device is configured to receive the authentication data to unlock the data storage device via a second control communication channel of the at least one control communication channel, and wherein the first control communication channel is different from the second control communication channel.
19 . The method according to claim 13 , further comprising configuring the data storage device, the method further comprising:
sending the first web application from the protected partition to the host device, wherein the host device instantiates the first web application on the browser of the host device;
receiving, from the host device, configuration data related to access control, including data related to the authentication data set;
storing, via the first web application, at least one record of the configuration data related to access control in the protected partition;
encrypting the data related to access control; and/or initializing the second web application including any one or more of:
generating any one or more of: the first interface, a second interface of the second web application configured to receive the unlock request from the host device, and/or a third interface of the second web application to present whether the data storage device is unlocked or not;
linking an authentication module of the at least one processor of the data storage device to the second web application; and/or
enabling encryption to the unlock request and/or the authentication data.
20 . A data storage device comprising:
at least one processor;
means for storing data, the data including program code that, when executed, emulates at least a webserver configured to provide a first web application to a browser of a host device to configure the data storage device, a second web application, wherein the second web application is different from the first web application and is executable the browser of the host device to unlock the data storage device;
means for communicatively coupling with the host device, via at least one control communication channel, wherein the at least one processor is configured to emulate a network adapter to the host device, wherein the at least one control communication channel is enabled by an Ethernet over USB (Universal Serial Bus) protocol driver, wherein the second web application is configured to specify an IP (Internet Protocol) address associated with the data storage device to unlock the data storage device via the at least one control communication channel,
means for receiving, via the at least one control communication channel, authentication data to unlock the data storage device, wherein the authentication data is received from the second web application instantiated at the browser of the host device;
means for verifying that the received authentication data corresponds to a record in an authentication data set configured by the first web application; and
means for unlocking the data storage device to enable access between the host device and the secured partition via a data communication channel, wherein the data communication channel is enabled by a USB mass storage driver.