Edge Device Private Information Backup Using Vault-Broker Trust

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for backing up and recovering private information from edge devices, such as cryptographic keys and account numbers, are insecure and burdensome, often compromising security and requiring significant infrastructure investment.

Innovation Solution

A system utilizing a vault-broker server to establish an implied circle of trust among edge devices, enabling secure backup and recovery of private information through encryption and a wrapping key mechanism, ensuring data is end-to-end encrypted and stored on surrogate edge devices within the same trust circle.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If private information is backed up on a personal computer or server, then backup availability is improved, but security level deteriorates

Engineering Contradiction:
Improvebackup availabilityVSAvoidsecurity level
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a secure element as an intermediary component that mediates between the edge device and backup storage. The secure element generates encrypted backup records using its private key and stores them on surrogate devices. This intermediary approach allows backup availability to improve while maintaining security, as the secure element's cryptographic protection ensures that even if backup storage is compromised, the private information remains protected.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If private information is stored on a centralized backup server, then backup accessibility is improved, but security vulnerability increases

Engineering Contradiction:
Improvebackup accessibilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the backup architecture by distributing backup records across multiple surrogate edge devices rather than concentrating them on a single centralized server. Each surrogate device stores encrypted backup records independently. This segmentation reduces security vulnerability because compromise of one surrogate device does not expose all private information, while still maintaining backup accessibility through the distributed network of surrogates.

Inventive Principle:
Principle #1Segmentation

3Reliability

If secure element backup mechanisms are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure element performs self-service by automatically generating encryption keys, creating encrypted backup records, and managing the backup process without requiring complex external security infrastructure. The secure element's embedded cryptographic capabilities enable it to autonomously protect private information during backup operations, reducing overall system complexity while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

4Ease of manufacture

If traditional backup storage methods are used, then implementation simplicity is improved, but security protection deteriorates

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity protection
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent changes the cryptographic parameters by using the secure element's private key to generate unique encryption keys for each backup record. This parameter change transforms ordinary backup storage into a secure backup system. The implementation remains relatively simple because the secure element handles the cryptographic operations automatically, while the security protection is dramatically improved through end-to-end encryption of backup records.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP4211867B1Backup and recovery of private information on edge devices onto surrogate edge devices
Publication Date: 2025.06.25 THALES DIS FRANCE SA
  • EP4211867B1 patent drawingFigure 1
  • EP4211867B1 patent drawingFigure 2
  • EP4211867B1 patent drawingFigure 3

AI summary

A system and method for backing up critical data of edge devices includes originator, surrogate, and target edge devices as well as a vault-broker server. The critical data, encrypted, is transmitted to and stored by a surrogate. The association of originator and surrogate is managed by the vault-broker server. Encryption protects the data from recovery by unauthorized parties while allowing surrogate edge devices to determine if recovery attempts are made by authorized parties.