Automatic Encryption Key Backup and Restore Mechanism

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information processing apparatuses require user intervention to backup and restore encryption keys, leading to data decryption issues when the controller board is replaced, as the encryption key is lost and not automatically recovered.

Innovation Solution

An information processing apparatus with an encryption chip for data encryption and decryption, a nonvolatile memory for storing a backup encryption key, and a control unit that automatically checks for decryption consistency and either restores or backs up the encryption key as necessary, ensuring seamless key management during controller board replacements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of repair

If the controller board is replaced to fix breakdown or malfunction, then the device can be repaired, but the encryption key stored in the encryption chip is lost and data cannot be decrypted

Engineering Contradiction:
Improvecontroller board replacementVSAvoiddata decryption capability
Core Design Contradiction:
Ease of repairVSReliability

Solution Approach 1:

The system performs preliminary action by automatically backing up the encryption key from the encryption chip to non-volatile memory before the controller board is replaced. When the controller board is replaced, the backup encryption key is automatically restored to the new encryption chip, ensuring data decryption capability is maintained without user intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy of the encryption key stored in the encryption chip and stores it in non-volatile memory. This copy serves as a backup that can be restored when the original encryption key is lost during controller board replacement, ensuring data can still be decrypted.

Inventive Principle:
Principle #26Copying

2Reliability

If the user manually backs up the encryption key to external storage medium, then the encryption key can be restored after controller board replacement, but the user must remember to perform the backup operation

Engineering Contradiction:
Improveencryption key restorationVSAvoiduser operation requirement
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-service by automatically backing up the encryption key from the encryption chip to non-volatile memory without requiring any user operation. The control unit detects when backup is needed and executes the backup and restoration processes automatically, eliminating the need for users to remember or perform manual backup operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses feedback by having the control unit detect whether the encryption key has been lost (by attempting decryption and detecting failure) and automatically trigger the backup or restoration process accordingly. This closed-loop control ensures the encryption key is managed properly without user intervention.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If automatic backup and restoration of encryption key is implemented, then user-friendliness is improved and data loss is prevented, but system complexity increases

Engineering Contradiction:
Improveautomatic key managementVSAvoidkey management system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The control unit performs multiple functions: it controls the encryption chip for data encryption/decryption, manages the backup encryption key in non-volatile memory, detects when backup or restoration is needed, and executes the appropriate operation. This multi-functionality consolidates the key management system into a single component, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system merges the backup and restoration operations into a unified automatic process managed by the control unit. Instead of having separate manual backup procedures and separate restoration procedures, the system combines them into one automatic key management function that handles both scenarios based on detected conditions.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10402346B2Information processing apparatus capable of backing up and restoring key for data encryption and method for controlling the same
Publication Date: 2019.09.03 CANON KK
  • US10402346B2 patent drawing
  • US10402346B2 patent drawing
  • US10402346B2 patent drawing

AI summary

An information processing apparatus includes a storage device configured to store data, an encryption chip configured to store an encryption key therein, a nonvolatile memory configured to store a backup encryption key, and a control unit configured to confirm whether the data stored in the storage device has been correctly decrypted by using the encryption key, and when the data has not been correctly decrypted, restore the backup encryption key to the encryption chip, and when the data has been correctly decrypted, back up the backup encryption key, which is a backup of the encryption key, stored in the encryption chip into the nonvolatile memory.