Cloud-Based Removable Drive Encryption Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing technologies fail to properly enforce removable drive encryption policies and manage recovery keys for Bring Your Own Device (BYOD) implementations when devices are outside the enterprise's intranet or private local area network, leading to potential data loss due to unknown recovery keys and password forgotten issues.

Innovation Solution

A cloud-based removable drive encryption policy enforcement and recovery key management system that uses a cloud computing environment to manage client devices, enabling encryption and recovery key storage accessible over public networks, ensuring compliance and recovery key availability regardless of network location.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If recovery keys are stored in a domain system of record, then security is improved, but accessibility is worsened when devices are outside the enterprise network

Engineering Contradiction:
ImprovesecurityVSAvoidaccessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a cloud-based key escrow service as an intermediary between the domain system of record and client devices. This mediator stores copies of recovery keys securely in the cloud, allowing users to retrieve them from any network location without directly accessing the domain system, thus maintaining security while improving accessibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If drive encryption is enforced, then security is improved, but usability is worsened when passwords are forgotten

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by automatically generating and storing recovery keys in the cloud escrow service before users potentially forget their passwords. This advance preparation ensures that recovery keys are readily available when needed, eliminating the usability problem of locked drives while maintaining encryption security.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If recovery keys are stored locally on devices, then accessibility is improved, but security is worsened due to potential data loss

Engineering Contradiction:
ImproveaccessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the recovery key storage function from local devices and relocates it to a secure cloud-based key escrow service. This separation allows devices to access encryption capabilities without storing sensitive recovery keys locally, improving security while maintaining accessibility through cloud-based retrieval mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11601271B2Cloud-based removable drive encryption policy enforcement and recovery key management
Publication Date: 2023.03.07 OMNISSA LLC
  • US11601271B2 patent drawing
  • US11601271B2 patent drawing
  • US11601271B2 patent drawing

AI summary

Examples of cloud-based removable drive encryption policy enforcement and recovery key management are described. In some examples, a removable drive encryption policy is received from a cloud-based management service. A removable drive is recognized by an operating system of a client device. An encryption command causes the operating system to request user password creation and encrypt the removable drive. A recovery key is identified from a write-output of the operating system. The recovery key is transmitted to the cloud-based management service for storage in a cloud-based removable drive recovery key escrow.