Intermediary Access Control Encryption for Read-Only Data Archiving

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing recording systems, especially mobile ones, lack adequate data protection measures such as encryption and authentication, making them vulnerable to data loss and unauthorized access, which is critical for legally compliant data processing and security.

Innovation Solution

Implement an access control device that encrypts data using a cryptographic secret and operates in different modes to allow read access while preventing write or delete access, ensuring the encrypted data includes identifying information without decryption, thus securing data integrity and identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If recording systems store data locally without encryption or authentication, then data access is simple and fast, but data security and protection against unauthorized access are compromised

Engineering Contradiction:
Improvedata securityVSAvoidaccess control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an access control device as an intermediary component positioned between the host apparatus and the data storage system. This mediator handles all authentication and encryption/decryption operations, allowing the recording system itself to remain simple while achieving strong security. The access control device manages cryptographic secrets and controls access to stored data without requiring the host apparatus to have built-in security capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If mobile recording systems are made portable and replaceable, then flexibility and adaptability improve, but vulnerability to loss and theft increases

Engineering Contradiction:
ImproveportabilityVSAvoidtheft risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the security-critical data storage function from the mobile recording system into a separate, removable data storage system that can be independently secured. The access control device and cryptographic secrets are separated from the host apparatus, allowing the storage medium to be physically removed and replaced while maintaining security through the access control mechanism. This enables portability while mitigating theft risk because stolen devices cannot access the encrypted data without proper authentication.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encryption is implemented in the recording system, then data protection improves, but computing power requirements and operational complexity increase

Engineering Contradiction:
Improvedata protectionVSAvoidcomputing power
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The access control device serves as a dedicated intermediary that handles all computationally intensive cryptographic operations. This separates the encryption/decryption workload from the host recording apparatus, allowing the recording system to maintain simple, low-power operation while still achieving strong encryption protection. The access control device can be optimized specifically for cryptographic operations without the overhead of full recording system functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12393740B2Methods and devices for secure access control to a data storage system and for data archiving
Publication Date: 2025.08.19 SWISSBIT AG
  • US12393740B2 patent drawing
  • US12393740B2 patent drawing
  • US12393740B2 patent drawing

AI summary

A method for secure access control to a data storage system for a host apparatus by means of an access control device, the method comprising: as part of a first mode of operation of the access control device, receiving user data from the host apparatus and transmitting it in unmodified or modified form to the data storage system for local storage; exchanging a first cryptographic secret with a computer system to enable encryption of data by the access control device in dependence on the first cryptographic secret; receiving a data read request for at least a portion of the user data stored in the data storage system; in response to the data read request, transitioning the access control device to a second mode of operation in which the access control device is configured to perform read access but not write or delete access to the data storage system; and in the second operating mode, retrieving user data requested according to the data read request from the data storage system, encrypting them using the first cryptographic secret (K) or a key derived therefrom according to a key generation rule and transmitting the user data encrypted in this way to a predetermined user data recipient; wherein the user data is processed as part of the method in such a way that the encrypted user data transmitted as part of the second operating mode represents information which can be extracted from it for the user data recipient and which represents an identity of the access control device and/or of the data storage system or allows a clear conclusion to be drawn therefrom.