After a long day messing with my PS3 HDD, some nice idea comes to my mind during nap.
As we all know, whole or almost whole space (depend, but this is not important now) is encrypted by unique pair of keys (or one key in case of NAND units). To read data from it, we need i.e EID Root Key (from which those keys are generated). But what if we can store this (or more) keys outside readable bound? Well, actually this is possible since PS3 firmware respect HPA limitation.
So! We can sacrifice...
HPA-Vault conception

So! We can sacrifice...
HPA-Vault conception