Encrypted Device Recovery Unlock Through Authorization Tokens

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users face difficulties in unlocking and recovering encrypted data on computing devices, particularly when the device is in recovery mode due to corrupted or compromised boot sequences, making testing and debugging challenging.

Innovation Solution

A secure unlocking and recovery process is facilitated by using an unlock module that obtains device information, verifies it with an authorization service, and requires a PIN or security account credentials to unlock encrypted data partitions, while leveraging TPM anti-hammering capabilities for secure access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption mechanisms are used to protect stored information, then data security is improved, but the ability to unlock and recover data in recovery mode deteriorates

Engineering Contradiction:
Improvedata securityVSAvoidunlock capability in recovery mode
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an authorization service as an intermediary between the encrypted device and the unlocking process. This service receives device information, verifies it, and provides authorization tokens that enable unlocking in recovery mode without compromising the encryption itself. The authorization service acts as a mediator that bridges the security requirements with the recovery needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary actions by storing device information and authorization credentials before the recovery scenario occurs. The authorization service pre-verifyes device identity and stores authentication data that can be quickly utilized when recovery mode is activated, avoiding the need for complex real-time verification during the critical recovery process.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If traditional unlocking methods are used in recovery mode, then data access is enabled, but security is compromised

Engineering Contradiction:
Improvedata access in recovery modeVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authorization service serves as a secure intermediary that mediates the unlocking process. Instead of directly accessing encryption keys in recovery mode, the system uses the authorization service to verify device identity and provide authorized access tokens. This maintains security by keeping the actual encryption mechanisms protected while enabling legitimate recovery operations through the intermediary.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates and uses authorization tokens as copies or representations of the actual encryption credentials. These tokens enable data access in recovery mode without exposing the master encryption keys. The token acts as a secure copy that provides sufficient authority for recovery operations while maintaining the integrity and security of the original encryption system.

Inventive Principle:
Principle #26Copying

3Reliability

If device information verification is implemented, then unauthorized access is prevented, but the unlocking process becomes more complex

Engineering Contradiction:
Improveaccess controlVSAvoidunlocking process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authorization service provides a universal verification mechanism that handles multiple verification requirements through a single integrated process. Rather than implementing separate verification steps for different recovery scenarios, the authorization service offers a multi-functional verification system that adapts to various device types and encryption schemes, simplifying the overall process despite the comprehensive security checks performed.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system implements self-service by having the device provide its own verification information to the authorization service. The device autonomously generates and transmits its identification data, and the authorization service independently performs verification and issues tokens without requiring manual intervention or complex external verification procedures. This self-service approach streamlines the process while maintaining rigorous access control.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12443699B2Unlock and recovery for encrypted devices
Publication Date: 2025.10.14 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12443699B2 patent drawing
  • US12443699B2 patent drawing
  • US12443699B2 patent drawing

AI summary

A computing device can perform operations to unlock encrypted volumes of the computing device while the computing device is in a recovery environment. In some examples, the computing device can work in conjunction with a test computing device to unlock the encrypted volumes using an unlock token and a PIN. In other examples, the computing device can perform operations without a test computing device. For example, the computing device can, while in the recovery environment, use credentials associated with a user of the computing device to obtain a recovery password to unlock keys for interpreting the encrypted volumes. In some examples, the computing device can use a shortened recovery password in conjunction with anti-hammering capabilities of a Trusted Platform Module in order to unlock keys for interpreting the encrypted volumes. These and other operations can facilitate secure unlock of volumes of encrypted data on a consumer device.