External Data Encryption Device for Secure Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing data stored on external storage devices are inadequate as they either require significant changes to the computer system configuration or do not effectively prevent access when the storage device and encryption device are stolen together.

Innovation Solution

A data processing device connected between a storage device and a controlling device that includes a receiving unit for commands, a determining unit to assess command executability, an encryption and decryption unit, and controlling units to manage data flow securely, ensuring that only valid commands are executed and data is encrypted or decrypted accordingly, with key information generated from unique system information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption and decryption functions are added within the computer system, then data security is improved, but the configuration of the computer system must be changed considerably

Engineering Contradiction:
Improvedata securityVSAvoidcomputer system configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an external encryption device as an intermediary component that bridges the computer system and external storage device. This mediator handles all encryption and decryption operations externally, allowing the computer system to maintain its original configuration while still achieving data security through the intermediate encryption layer

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption and decryption functions are added to the external storage device, then data security is improved, but it is not possible to use general external storage devices

Engineering Contradiction:
Improvedata securityVSAvoidstorage device compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The external encryption device serves as a universal intermediary that works with any standard external storage device. It provides the encryption functionality without modifying the storage device itself, maintaining compatibility with general storage devices while securing the data through the intermediate encryption layer

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If key information is stored on a removable device such as an IC card, then data security against theft is improved, but when the external storage device and encryption device are stolen together, data can still be accessed

Engineering Contradiction:
Improvedata security against theftVSAvoiddata accessibility after theft
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent segments the security system into three independent components: the computer system, the external encryption device, and the key information stored on a removable medium. This segmentation ensures that even if two components are stolen together, the third component (key information) remains secure and cannot be used to decrypt the data without the proper authentication

Inventive Principle:
Principle #1Segmentation

4Reliability

If a bridging device is provided between computer system and external storage device, then data security is improved, but the configuration of the computer system must be changed considerably

Engineering Contradiction:
Improvedata securityVSAvoidsystem configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external encryption device is designed as a universal bridge that interfaces with standard computer systems and storage devices without requiring specialized configurations. It provides multi-functional capabilities including encryption, decryption, and key management through a standardized interface, avoiding the need for complex system modifications

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8839359B2Data processing device and data processing method
Publication Date: 2014.09.16 CANON KK
  • US8839359B2 patent drawing
  • US8839359B2 patent drawing
  • US8839359B2 patent drawing

AI summary

A data encryption device is connected between an HDD and an HDD controller that controls the HDD. The data encryption device encrypts data that is stored from the HDD controller to the HDD, and decrypts data that is read from the HDD. A CPU of the data encryption device receives a command issued from the HDD controller to the HDD, and determines whether the command is executable at the HDD. When it is determined that the command is executable, the command is issued to the HDD. On the other hand, when it is determined that the command is unexecutable, the CPU prohibits issuance of the command to the HDD. Furthermore, when a command issued to the HDD is a specific command, the CPU bypasses data transferred between the HDD controller and the HDD without encryption or decryption.