External Data Encryption Device for Secure Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for securing data stored on external storage devices are inadequate as they either require significant changes to the computer system configuration or do not effectively prevent access when the storage device and encryption device are stolen together.
Innovation Solution
A data processing device connected between a storage device and a controlling device that includes a receiving unit for commands, a determining unit to assess command executability, an encryption and decryption unit, and controlling units to manage data flow securely, ensuring that only valid commands are executed and data is encrypted or decrypted accordingly, with key information generated from unique system information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and decryption functions are added within the computer system, then data security is improved, but the configuration of the computer system must be changed considerably
Solution Approach 1:
The patent introduces an external encryption device as an intermediary component that bridges the computer system and external storage device. This mediator handles all encryption and decryption operations externally, allowing the computer system to maintain its original configuration while still achieving data security through the intermediate encryption layer
2Reliability
If encryption and decryption functions are added to the external storage device, then data security is improved, but it is not possible to use general external storage devices
Solution Approach 1:
The external encryption device serves as a universal intermediary that works with any standard external storage device. It provides the encryption functionality without modifying the storage device itself, maintaining compatibility with general storage devices while securing the data through the intermediate encryption layer
3Reliability
If key information is stored on a removable device such as an IC card, then data security against theft is improved, but when the external storage device and encryption device are stolen together, data can still be accessed
Solution Approach 1:
The patent segments the security system into three independent components: the computer system, the external encryption device, and the key information stored on a removable medium. This segmentation ensures that even if two components are stolen together, the third component (key information) remains secure and cannot be used to decrypt the data without the proper authentication
4Reliability
If a bridging device is provided between computer system and external storage device, then data security is improved, but the configuration of the computer system must be changed considerably
Solution Approach 1:
The external encryption device is designed as a universal bridge that interfaces with standard computer systems and storage devices without requiring specialized configurations. It provides multi-functional capabilities including encryption, decryption, and key management through a standardized interface, avoiding the need for complex system modifications
Data Source
AI summary
A data encryption device is connected between an HDD and an HDD controller that controls the HDD. The data encryption device encrypts data that is stored from the HDD controller to the HDD, and decrypts data that is read from the HDD. A CPU of the data encryption device receives a command issued from the HDD controller to the HDD, and determines whether the command is executable at the HDD. When it is determined that the command is executable, the command is issued to the HDD. On the other hand, when it is determined that the command is unexecutable, the CPU prohibits issuance of the command to the HDD. Furthermore, when a command issued to the HDD is a specific command, the CPU bypasses data transferred between the HDD controller and the HDD without encryption or decryption.


