Encrypted Data Recovery via Intermediary Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure storage devices, such as USB memory devices, face issues with data security and accessibility, as they can be stolen and accessed by thieves, and their security measures often prevent authorized access, especially when the user code or decryption key is unavailable.

Innovation Solution

A software product and system that allows recovery of encrypted data from a target secure storage device by sending a transfer command, receiving an authorization request, responding to it, and decrypting the data using encryption keys from authorized secure storage devices, which can include biometric identifiers for authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security measures are implemented on USB memory devices to prevent unauthorized access, then data security is improved, but authorized access becomes difficult when user code or decryption key is unavailable

Engineering Contradiction:
Improvedata securityVSAvoidauthorized access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an intermediary recovery system that mediates between the locked data and the authorized user. When the primary authentication fails, the intermediary recovery server and recovery key provide an alternative path for authorized access without compromising the original security measures. The recovery key acts as a mediator that can unlock the data when the user code is unavailable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by pre-configuring recovery keys and recovery servers before the security lockout occurs. The authorized user sets up the recovery mechanism in advance, storing recovery keys on secure recovery servers or in secure locations. This preliminary preparation ensures that authorized access is available when needed without compromising the security measures.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If password-based security is used on USB memory devices, then unauthorized access is prevented, but the device can still be stolen and accessed by thieves through brute force attacks

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidtheft and brute force attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security system into multiple independent components: the primary password protection, the recovery key system, and the authorization mechanism. By dividing the security into separate layers, the system prevents brute force attacks from compromising the entire system. Even if the password is cracked, the segmented security structure maintains protection through additional authorization requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary authorization layer between the password and the data access. The recovery key and authorization server act as mediators that verify the legitimacy of access requests. This intermediary mechanism prevents thieves from simply using brute force on the password, as additional authorization from the recovery system is required.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If data is encrypted and stored on portable devices for mobility, then data accessibility is improved, but security risks increase due to potential theft and unauthorized access

Engineering Contradiction:
Improvedata mobility and accessibilityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by pre-configuring the encryption keys and recovery mechanisms before the portable device is used. The authorization system and recovery keys are established in advance, allowing the device to maintain strong security while being portable. This preliminary setup enables the device to provide both mobility and security without requiring complex security measures during use.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8438647B2Recovery of encrypted data from a secure storage device
Publication Date: 2013.05.07 DATA LOCKER INC
  • US8438647B2 patent drawing
  • US8438647B2 patent drawing
  • US8438647B2 patent drawing

AI summary

An exemplary software product to recover encrypted data from a target secure storage device can comprise software operational when executed by a processor to receive a recovery request to recovery the encrypted data, send a transfer command to the target secure storage device, receive an authorization request from the target secure storage device in response to the transfer command, respond to the authorization request, and receive the encrypted data from the target secure storage device.