Encrypted Data Recovery via Intermediary Authorization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure storage devices, such as USB memory devices, face issues with data security and accessibility, as they can be stolen and accessed by thieves, and their security measures often prevent authorized access, especially when the user code or decryption key is unavailable.
Innovation Solution
A software product and system that allows recovery of encrypted data from a target secure storage device by sending a transfer command, receiving an authorization request, responding to it, and decrypting the data using encryption keys from authorized secure storage devices, which can include biometric identifiers for authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security measures are implemented on USB memory devices to prevent unauthorized access, then data security is improved, but authorized access becomes difficult when user code or decryption key is unavailable
Solution Approach 1:
The patent introduces an intermediary recovery system that mediates between the locked data and the authorized user. When the primary authentication fails, the intermediary recovery server and recovery key provide an alternative path for authorized access without compromising the original security measures. The recovery key acts as a mediator that can unlock the data when the user code is unavailable.
Solution Approach 2:
The patent implements preliminary action by pre-configuring recovery keys and recovery servers before the security lockout occurs. The authorized user sets up the recovery mechanism in advance, storing recovery keys on secure recovery servers or in secure locations. This preliminary preparation ensures that authorized access is available when needed without compromising the security measures.
2Reliability
If password-based security is used on USB memory devices, then unauthorized access is prevented, but the device can still be stolen and accessed by thieves through brute force attacks
Solution Approach 1:
The patent segments the security system into multiple independent components: the primary password protection, the recovery key system, and the authorization mechanism. By dividing the security into separate layers, the system prevents brute force attacks from compromising the entire system. Even if the password is cracked, the segmented security structure maintains protection through additional authorization requirements.
Solution Approach 2:
The patent introduces an intermediary authorization layer between the password and the data access. The recovery key and authorization server act as mediators that verify the legitimacy of access requests. This intermediary mechanism prevents thieves from simply using brute force on the password, as additional authorization from the recovery system is required.
3Ease of operation
If data is encrypted and stored on portable devices for mobility, then data accessibility is improved, but security risks increase due to potential theft and unauthorized access
Solution Approach 1:
The patent applies preliminary action by pre-configuring the encryption keys and recovery mechanisms before the portable device is used. The authorization system and recovery keys are established in advance, allowing the device to maintain strong security while being portable. This preliminary setup enables the device to provide both mobility and security without requiring complex security measures during use.
Data Source
AI summary
An exemplary software product to recover encrypted data from a target secure storage device can comprise software operational when executed by a processor to receive a recovery request to recovery the encrypted data, send a transfer command to the target secure storage device, receive an authorization request from the target secure storage device in response to the transfer command, respond to the authorization request, and receive the encrypted data from the target secure storage device.


