Cloud-Based Removable Drive Encryption Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies fail to properly enforce removable drive encryption policies and manage recovery keys for Bring Your Own Device (BYOD) implementations when devices are outside the enterprise's intranet or private local area network, leading to potential data loss due to unknown recovery keys and password forgotten issues.
Innovation Solution
A cloud-based removable drive encryption policy enforcement and recovery key management system that uses a cloud computing environment to manage client devices, enabling encryption and recovery key storage accessible over public networks, ensuring compliance and recovery key availability regardless of network location.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If recovery keys are stored in a domain system of record, then security is improved, but accessibility is worsened when devices are outside the enterprise network
Solution Approach 1:
The patent introduces a cloud-based key escrow service as an intermediary between the domain system of record and client devices. This mediator stores copies of recovery keys securely in the cloud, allowing users to retrieve them from any network location without directly accessing the domain system, thus maintaining security while improving accessibility.
2Reliability
If drive encryption is enforced, then security is improved, but usability is worsened when passwords are forgotten
Solution Approach 1:
The patent implements preliminary action by automatically generating and storing recovery keys in the cloud escrow service before users potentially forget their passwords. This advance preparation ensures that recovery keys are readily available when needed, eliminating the usability problem of locked drives while maintaining encryption security.
3Ease of operation
If recovery keys are stored locally on devices, then accessibility is improved, but security is worsened due to potential data loss
Solution Approach 1:
The patent extracts the recovery key storage function from local devices and relocates it to a secure cloud-based key escrow service. This separation allows devices to access encryption capabilities without storing sensitive recovery keys locally, improving security while maintaining accessibility through cloud-based retrieval mechanisms.
Data Source
AI summary
Examples of cloud-based removable drive encryption policy enforcement and recovery key management are described. In some examples, a removable drive encryption policy is received from a cloud-based management service. A removable drive is recognized by an operating system of a client device. An encryption command causes the operating system to request user password creation and encrypt the removable drive. A recovery key is identified from a write-output of the operating system. The recovery key is transmitted to the cloud-based management service for storage in a cloud-based removable drive recovery key escrow.


