Encryption Circuit Segments Password Storage from Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable storage devices lack effective encryption mechanisms, making confidential data vulnerable to unauthorized access if the password is stolen or compromised, leading to security risks.

Innovation Solution

An encryption and decryption device comprising a storage element, a control element, and an encryption and decryption circuit that receives and stores a password, enables encryption or decryption of data in a portable storage device, and clears the password post-operation, ensuring that even if the password is obtained, decryption requires a specific device with the encryption and decryption circuit.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a built-in encryption mechanism with password protection is implemented in portable storage devices, then data security is improved, but the system complexity increases and the password itself becomes a single point of failure that can be stolen or cracked

Engineering Contradiction:
Improvedata securityVSAvoidencryption mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The encryption system is segmented into two distinct parts: a password storage component and an encryption circuit component. The password is stored in a secure memory element within the encryption device, while the encryption/decryption operations are performed by a separate encryption circuit. This segmentation ensures that even if the password is compromised, the encryption circuit itself remains the gatekeeper that must physically be present to decrypt data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The encryption circuit acts as an intermediary between the stored password and the data. Instead of directly using the password to protect data, the system introduces the encryption circuit as a mediator that must process both the password and the data together. This intermediary layer adds a critical security step: the encryption circuit verifies the password and then performs encryption/decryption operations, ensuring that knowledge of the password alone is insufficient without the physical encryption circuit.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the password is stored in the portable storage device for encryption operations, then encryption functionality is enabled, but the stored password becomes vulnerable to theft or cracking attacks

Engineering Contradiction:
Improveencryption functionalityVSAvoidpassword theft or cracking risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The password is pre-stored in a secure memory element within the encryption device before any data encryption or decryption operations occur. This preliminary storage in a protected environment ensures the password is never exposed during transmission or processing. The password remains securely stored until the encryption circuit needs to use it, at which point it is processed through secure internal pathways and then cleared from temporary registers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The password is temporarily held in the encryption circuit's internal memory or registers only during the encryption/decryption operation, then immediately discarded (cleared) after use. This approach allows the system to have the password available when needed while ensuring it does not persist in vulnerable states. The password is recovered (re-loaded) only when the next encryption operation is initiated, creating a continuous cycle of secure temporary storage and disposal.

Inventive Principle:
Principle #34Discarding and recovering

3Ease of operation

If conventional password-based encryption is used in portable storage devices, then data can be accessed with a password, but the data can be read in any computer once the password is obtained, creating security risks

Engineering Contradiction:
Improvepassword-based accessVSAvoiddata security against unauthorized access
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The encryption circuit serves as a mandatory intermediary that physically must be present to decrypt data. Even with the password, unauthorized systems cannot access the data without connecting to a device containing the specific encryption circuit. This intermediary layer transforms the security model from 'password-only' to 'password plus physical device', where the encryption circuit validates and processes the password in a controlled environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a functional copy mechanism where the encryption circuit itself becomes the key to data access. Instead of relying solely on the password as the unique identifier, the system effectively copies the security requirement to include the physical presence of the encryption circuit. This means the data can be accessed on any computer only if that computer has the encryption circuit, creating a portable security credential rather than a static password.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9158943B2Encryption and decryption device for portable storage device and encryption and decryption method thereof
Publication Date: 2015.10.13 ASMEDIA TECHNOLOGY INC
  • US9158943B2 patent drawing
  • US9158943B2 patent drawing
  • US9158943B2 patent drawing

AI summary

An encryption and decryption device for a portable storage device and an encryption and decryption method thereof are provided. The encryption and decryption device includes a storage element, a control element and an encryption and decryption circuit. The control element receives a password, saves the password to the storage element and provides an encryption and decryption command. The encryption and decryption circuit is electrically connected to a portable storage device, receives the encryption and decryption command, reads the password stored in the storage element according to the encryption and decryption command, and encrypts or decrypts data stored in the portable storage device by utilizing the password according to whether the data have been encrypted. After the data are encrypted or decrypted, the encryption and decryption circuit clears the password in the storage element.