Encrypted Device Recovery Unlock Through Authorization Tokens
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face difficulties in unlocking and recovering encrypted data on computing devices, particularly when the device is in recovery mode due to corrupted or compromised boot sequences, making testing and debugging challenging.
Innovation Solution
A secure unlocking and recovery process is facilitated by using an unlock module that obtains device information, verifies it with an authorization service, and requires a PIN or security account credentials to unlock encrypted data partitions, while leveraging TPM anti-hammering capabilities for secure access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption mechanisms are used to protect stored information, then data security is improved, but the ability to unlock and recover data in recovery mode deteriorates
Solution Approach 1:
The patent introduces an authorization service as an intermediary between the encrypted device and the unlocking process. This service receives device information, verifies it, and provides authorization tokens that enable unlocking in recovery mode without compromising the encryption itself. The authorization service acts as a mediator that bridges the security requirements with the recovery needs.
Solution Approach 2:
The system performs preliminary actions by storing device information and authorization credentials before the recovery scenario occurs. The authorization service pre-verifyes device identity and stores authentication data that can be quickly utilized when recovery mode is activated, avoiding the need for complex real-time verification during the critical recovery process.
2Ease of operation
If traditional unlocking methods are used in recovery mode, then data access is enabled, but security is compromised
Solution Approach 1:
The authorization service serves as a secure intermediary that mediates the unlocking process. Instead of directly accessing encryption keys in recovery mode, the system uses the authorization service to verify device identity and provide authorized access tokens. This maintains security by keeping the actual encryption mechanisms protected while enabling legitimate recovery operations through the intermediary.
Solution Approach 2:
The system creates and uses authorization tokens as copies or representations of the actual encryption credentials. These tokens enable data access in recovery mode without exposing the master encryption keys. The token acts as a secure copy that provides sufficient authority for recovery operations while maintaining the integrity and security of the original encryption system.
3Reliability
If device information verification is implemented, then unauthorized access is prevented, but the unlocking process becomes more complex
Solution Approach 1:
The authorization service provides a universal verification mechanism that handles multiple verification requirements through a single integrated process. Rather than implementing separate verification steps for different recovery scenarios, the authorization service offers a multi-functional verification system that adapts to various device types and encryption schemes, simplifying the overall process despite the comprehensive security checks performed.
Solution Approach 2:
The system implements self-service by having the device provide its own verification information to the authorization service. The device autonomously generates and transmits its identification data, and the authorization service independently performs verification and issues tokens without requiring manual intervention or complex external verification procedures. This self-service approach streamlines the process while maintaining rigorous access control.
Data Source
AI summary
A computing device can perform operations to unlock encrypted volumes of the computing device while the computing device is in a recovery environment. In some examples, the computing device can work in conjunction with a test computing device to unlock the encrypted volumes using an unlock token and a PIN. In other examples, the computing device can perform operations without a test computing device. For example, the computing device can, while in the recovery environment, use credentials associated with a user of the computing device to obtain a recovery password to unlock keys for interpreting the encrypted volumes. In some examples, the computing device can use a shortened recovery password in conjunction with anti-hammering capabilities of a Trusted Platform Module in order to unlock keys for interpreting the encrypted volumes. These and other operations can facilitate secure unlock of volumes of encrypted data on a consumer device.


