A portable security system mounted in a portable data storage cartridge
for managing access by users to the cartridge. A programmable computer
processor mounted in the cartridge is powered by and transfers data to a
data storage drive via a wireless RF interface, when mounted in the
drive. A user table has a unique user identifier for each authorized user
and lists permitted activities of the user for the cartridge. The user
identifier comprises a user symbol and a user decrypting sender public
key. An authentication message from the authorized user is encrypted by a
sender private key and a receiver public key. The cartridge processor
decrypts the message employing a receiver private key and the sender
public key, whereby the user authentication message is known to have come
from the user and grants access to the user for the listed activities for
the cartridge.