Edge Device Private Information Backup Using Vault-Broker Trust
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for backing up and recovering private information from edge devices, such as cryptographic keys and account numbers, are insecure and burdensome, often compromising security and requiring significant infrastructure investment.
Innovation Solution
A system utilizing a vault-broker server to establish an implied circle of trust among edge devices, enabling secure backup and recovery of private information through encryption and a wrapping key mechanism, ensuring data is end-to-end encrypted and stored on surrogate edge devices within the same trust circle.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If private information is backed up on a personal computer or server, then backup availability is improved, but security level deteriorates
Solution Approach 1:
The patent introduces a secure element as an intermediary component that mediates between the edge device and backup storage. The secure element generates encrypted backup records using its private key and stores them on surrogate devices. This intermediary approach allows backup availability to improve while maintaining security, as the secure element's cryptographic protection ensures that even if backup storage is compromised, the private information remains protected.
2Ease of operation
If private information is stored on a centralized backup server, then backup accessibility is improved, but security vulnerability increases
Solution Approach 1:
The patent segments the backup architecture by distributing backup records across multiple surrogate edge devices rather than concentrating them on a single centralized server. Each surrogate device stores encrypted backup records independently. This segmentation reduces security vulnerability because compromise of one surrogate device does not expose all private information, while still maintaining backup accessibility through the distributed network of surrogates.
3Reliability
If secure element backup mechanisms are implemented, then security is improved, but device complexity increases
Solution Approach 1:
The secure element performs self-service by automatically generating encryption keys, creating encrypted backup records, and managing the backup process without requiring complex external security infrastructure. The secure element's embedded cryptographic capabilities enable it to autonomously protect private information during backup operations, reducing overall system complexity while maintaining high security standards.
4Ease of manufacture
If traditional backup storage methods are used, then implementation simplicity is improved, but security protection deteriorates
Solution Approach 1:
The patent changes the cryptographic parameters by using the secure element's private key to generate unique encryption keys for each backup record. This parameter change transforms ordinary backup storage into a secure backup system. The implementation remains relatively simple because the secure element handles the cryptographic operations automatically, while the security protection is dramatically improved through end-to-end encryption of backup records.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system and method for backing up critical data of edge devices includes originator, surrogate, and target edge devices as well as a vault-broker server. The critical data, encrypted, is transmitted to and stored by a surrogate. The association of originator and surrogate is managed by the vault-broker server. Encryption protects the data from recovery by unauthorized parties while allowing surrogate edge devices to determine if recovery attempts are made by authorized parties.