Distributed Security Key for Mobile Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data protection methods for mobile devices are vulnerable as they store both data and security keys on the same device, making them susceptible to loss or theft, and are often costly due to the need for dedicated encryption devices.
Innovation Solution
A method that separates data protection by using an outer security key generated from a unique device identifier, a unique external memory device identifier, and a personal identification number, with the encrypted inner security key stored on an external memory device, allowing secure encryption and decryption of data without the need for dedicated hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If data and security key are stored on the same mobile device, then data protection is simplified, but security vulnerability increases when device is lost or stolen
Solution Approach 1:
The security system is segmented into two parts: the mobile device stores encrypted data with a first encryption key, while the external memory device stores the second encryption key. This segmentation separates the data and protection mechanism across different physical locations, maintaining simplicity while enhancing security against device loss or theft.
Solution Approach 2:
The second encryption key is extracted from the mobile device and stored on an external memory device. This extraction removes the critical security component from the potentially compromised device, allowing data to remain protected even if the device is lost or stolen, while keeping the protection mechanism accessible when needed.
2Reliability
If dedicated devices are used for generating encryption keys, then security is enhanced, but cost increases considerably
Solution Approach 1:
The external memory device performs multiple functions: it stores the second encryption key, can be coupled to the mobile device for decryption operations, and serves as a portable security anchor. This multi-functionality eliminates the need for separate dedicated key generation devices, reducing cost while maintaining enhanced security.
Solution Approach 2:
The mobile device itself generates the first encryption key and performs the encryption operations, while the external memory device stores the second key. This self-service approach eliminates dependency on expensive dedicated hardware devices, as the existing mobile device capabilities are充分利用 to provide security functions.
3Reliability
If complex passphrases are used for data access, then security is improved, but user convenience deteriorates due to difficulty in remembering
Solution Approach 1:
The system uses encryption keys as intermediaries between the user and the data protection mechanism. Instead of requiring users to directly manage complex passphrases, the keys automatically handle security operations when the external memory device is coupled to the mobile device, maintaining security while improving user convenience.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
For protecting data stored in an electronic device (110), an inner security key encrypting and decrypting data stored in the electronic device (110) is encrypted with an outer security key (50). The outer security key (50) is stored on an external memory to be coupled to the electronic device (110). The outer security key (50) is generated from at least a unique identifier of the electronic device (110), a unique identifier of the external memory device (120), and a personal identification number. Additional constituents of the outer security key (50) may be provided, e.g., an identifier of an auxiliary device (140) to be coupled to the electronic device (110).