Backup Encryption Key Management for Secure Data Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data backup systems expose sensitive information to security risks by decrypting data during the backup process, lack unattended backup capabilities, and impose integration challenges between backup and security systems, leading to limitations in data recovery and access control.

Innovation Solution

A system that distinguishes between backup agents and other clients, providing encrypted data to backup systems while maintaining separate encryption keys for users and backup procedures, enabling unattended backups and seamless integration of backup and security systems, and allowing secure data recovery on any device or location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encrypted data is decrypted before being provided to a backup agent, then the backup system can access and store the data, but security risks are exposed during the backup procedure

Engineering Contradiction:
Improvebackup capabilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the backup system into multiple components: a backup agent that requests data, a security module that controls decryption, and a backup storage system. The data remains encrypted during transmission and is only decrypted within the secure backup storage environment, preventing exposure of sensitive data during the backup procedure while maintaining backup functionality.

Inventive Principle:
Principle #1Segmentation

2Ease of repair

If data is stored in decrypted form on a backup system, then recovery is easier, but security is compromised

Engineering Contradiction:
Improvedata recoveryVSAvoidsecurity risk
Core Design Contradiction:
Ease of repairVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary encryption of data before backup using a backup encryption key that is generated and stored securely within the backup storage system. This preliminary security measure ensures that data remains encrypted throughout the backup process and is only decrypted when authorized recovery operations are performed, maintaining both security and recoverability.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If separate encryption keys are used for users and backup procedures, then security is enhanced, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidkey management
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces a backup encryption key as an intermediary that bridges user data and backup storage. The user's original encryption key remains unchanged for accessing data on the original device, while the backup encryption key is generated specifically for backup operations and stored within the backup storage system. This intermediary key simplifies key management by isolating backup-specific cryptographic operations from user-facing operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If backup systems require integration with security systems, then data protection is improved, but integration challenges and complexity arise

Engineering Contradiction:
Improvedata protectionVSAvoidsystem integration
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent merges the security functionality and backup functionality into a unified system architecture. The security module and backup storage system are integrated such that the backup storage system inherently provides security through encrypted storage, eliminating the need for separate complex integration between independent security and backup systems. The backup agent communicates with both security and storage components through a unified interface.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9740567B2System and method for secured backup of data
Publication Date: 2017.08.22 SUPERCOM IP LLC
  • US9740567B2 patent drawing
  • US9740567B2 patent drawing
  • US9740567B2 patent drawing

AI summary

A system and method of selectively providing encrypted data is provided. Embodiments of the invention may store data in encrypted form on a storage device. Embodiments of the invention may selectively provide encrypted or decrypted data to a requestor of data based on configuration or other parameters. A filter driver or other module or unit may examine a request for, or communication of data from the storage device and may determine if data is to be provided in encrypted or decrypted form. Decrypted data may be provided to a caching system. A filter driver or other module or unit may examine a request for, or communication of data from the caching system. Data provided from the caching system may be selectively encrypted based on configuration or other parameters.