Encryption Circuit Segments Password Storage from Data Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Portable storage devices lack effective encryption mechanisms, making confidential data vulnerable to unauthorized access if the password is stolen or compromised, leading to security risks.
Innovation Solution
An encryption and decryption device comprising a storage element, a control element, and an encryption and decryption circuit that receives and stores a password, enables encryption or decryption of data in a portable storage device, and clears the password post-operation, ensuring that even if the password is obtained, decryption requires a specific device with the encryption and decryption circuit.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a built-in encryption mechanism with password protection is implemented in portable storage devices, then data security is improved, but the system complexity increases and the password itself becomes a single point of failure that can be stolen or cracked
Solution Approach 1:
The encryption system is segmented into two distinct parts: a password storage component and an encryption circuit component. The password is stored in a secure memory element within the encryption device, while the encryption/decryption operations are performed by a separate encryption circuit. This segmentation ensures that even if the password is compromised, the encryption circuit itself remains the gatekeeper that must physically be present to decrypt data.
Solution Approach 2:
The encryption circuit acts as an intermediary between the stored password and the data. Instead of directly using the password to protect data, the system introduces the encryption circuit as a mediator that must process both the password and the data together. This intermediary layer adds a critical security step: the encryption circuit verifies the password and then performs encryption/decryption operations, ensuring that knowledge of the password alone is insufficient without the physical encryption circuit.
2Adaptability or versatility
If the password is stored in the portable storage device for encryption operations, then encryption functionality is enabled, but the stored password becomes vulnerable to theft or cracking attacks
Solution Approach 1:
The password is pre-stored in a secure memory element within the encryption device before any data encryption or decryption operations occur. This preliminary storage in a protected environment ensures the password is never exposed during transmission or processing. The password remains securely stored until the encryption circuit needs to use it, at which point it is processed through secure internal pathways and then cleared from temporary registers.
Solution Approach 2:
The password is temporarily held in the encryption circuit's internal memory or registers only during the encryption/decryption operation, then immediately discarded (cleared) after use. This approach allows the system to have the password available when needed while ensuring it does not persist in vulnerable states. The password is recovered (re-loaded) only when the next encryption operation is initiated, creating a continuous cycle of secure temporary storage and disposal.
3Ease of operation
If conventional password-based encryption is used in portable storage devices, then data can be accessed with a password, but the data can be read in any computer once the password is obtained, creating security risks
Solution Approach 1:
The encryption circuit serves as a mandatory intermediary that physically must be present to decrypt data. Even with the password, unauthorized systems cannot access the data without connecting to a device containing the specific encryption circuit. This intermediary layer transforms the security model from 'password-only' to 'password plus physical device', where the encryption circuit validates and processes the password in a controlled environment.
Solution Approach 2:
The system creates a functional copy mechanism where the encryption circuit itself becomes the key to data access. Instead of relying solely on the password as the unique identifier, the system effectively copies the security requirement to include the physical presence of the encryption circuit. This means the data can be accessed on any computer only if that computer has the encryption circuit, creating a portable security credential rather than a static password.
Data Source
AI summary
An encryption and decryption device for a portable storage device and an encryption and decryption method thereof are provided. The encryption and decryption device includes a storage element, a control element and an encryption and decryption circuit. The control element receives a password, saves the password to the storage element and provides an encryption and decryption command. The encryption and decryption circuit is electrically connected to a portable storage device, receives the encryption and decryption command, reads the password stored in the storage element according to the encryption and decryption command, and encrypts or decrypts data stored in the portable storage device by utilizing the password according to whether the data have been encrypted. After the data are encrypted or decrypted, the encryption and decryption circuit clears the password in the storage element.


