Distributed Security Key for Mobile Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data protection methods for mobile devices are vulnerable as they store both data and security keys on the same device, making them susceptible to loss or theft, and are often costly due to the need for dedicated encryption devices.

Innovation Solution

A method that separates data protection by using an outer security key generated from a unique device identifier, a unique external memory device identifier, and a personal identification number, with the encrypted inner security key stored on an external memory device, allowing secure encryption and decryption of data without the need for dedicated hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data and security key are stored on the same mobile device, then data protection is simplified, but security vulnerability increases when device is lost or stolen

Engineering Contradiction:
Improvedata protection simplicityVSAvoidsecurity security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The security system is segmented into two parts: the mobile device stores encrypted data with a first encryption key, while the external memory device stores the second encryption key. This segmentation separates the data and protection mechanism across different physical locations, maintaining simplicity while enhancing security against device loss or theft.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The second encryption key is extracted from the mobile device and stored on an external memory device. This extraction removes the critical security component from the potentially compromised device, allowing data to remain protected even if the device is lost or stolen, while keeping the protection mechanism accessible when needed.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If dedicated devices are used for generating encryption keys, then security is enhanced, but cost increases considerably

Engineering Contradiction:
ImprovesecurityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The external memory device performs multiple functions: it stores the second encryption key, can be coupled to the mobile device for decryption operations, and serves as a portable security anchor. This multi-functionality eliminates the need for separate dedicated key generation devices, reducing cost while maintaining enhanced security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The mobile device itself generates the first encryption key and performs the encryption operations, while the external memory device stores the second key. This self-service approach eliminates dependency on expensive dedicated hardware devices, as the existing mobile device capabilities are充分利用 to provide security functions.

Inventive Principle:
Principle #25Self-service

3Reliability

If complex passphrases are used for data access, then security is improved, but user convenience deteriorates due to difficulty in remembering

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses encryption keys as intermediaries between the user and the data protection mechanism. Instead of requiring users to directly manage complex passphrases, the keys automatically handle security operations when the external memory device is coupled to the mobile device, maintaining security while improving user convenience.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2689367B1Data protection using distributed security key
Publication Date: 2019.06.19 SONY ERICSSON MOBILE COMMUNICATIONS AB
  • EP2689367B1 patent drawingFigure 1
  • EP2689367B1 patent drawingFigure 2
  • EP2689367B1 patent drawingFigure 3

AI summary

For protecting data stored in an electronic device (110), an inner security key encrypting and decrypting data stored in the electronic device (110) is encrypted with an outer security key (50). The outer security key (50) is stored on an external memory to be coupled to the electronic device (110). The outer security key (50) is generated from at least a unique identifier of the electronic device (110), a unique identifier of the external memory device (120), and a personal identification number. Additional constituents of the outer security key (50) may be provided, e.g., an identifier of an auxiliary device (140) to be coupled to the electronic device (110).