Hardware-Based File Expiry Timer Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of files stored in cloud storage is compromised due to unauthorized access, particularly in sensitive fields like law and medicine, where data protection is critical, and existing solutions fail to effectively manage data security while allowing access from multiple devices.

Innovation Solution

Implementing a hardware-based expiry timer enforcement system using trusted execution environments (TEEs) to generate encryption keys and certificates with expiration information, ensuring secure storage and access by encrypting files and storing them in cloud storage, with only authorized devices able to decrypt based on valid expiry information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If files are stored remotely in cloud storage for multi-device access, then accessibility and convenience are improved, but security and control over data access are worsened

Engineering Contradiction:
Improvemulti-device accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the security control mechanism into distributed hardware security modules across multiple trusted devices. Each device maintains its own security context and expiry timer state independently, allowing secure multi-device access without centralizing security control in a single point of failure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces hardware-based expiry timers as an intermediary mechanism between the cloud storage system and access requests. These timers act as mediators that automatically enforce access policies without requiring continuous human intervention or complex software-based authentication systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based expiry timers are implemented for automatic access control, then security is improved, but device complexity and implementation difficulty are worsened

Engineering Contradiction:
Improveaccess control securityVSAvoidhardware implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware security modules are designed to autonomously manage their own security state, including automatically tracking expiry timers and enforcing access decisions without requiring external management overhead. This self-service capability reduces the operational complexity despite the hardware complexity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes the security enforcement parameter from software-based policy evaluation to hardware-based timer enforcement. This parameter change shifts the complexity from software management to hardware implementation, but provides more reliable and consistent security enforcement.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS12113916B2Method and apparatus for hardware based file/document expiry timer enforcement
Publication Date: 2024.10.08 MCAFEE LLC
  • US12113916B2 patent drawing
  • US12113916B2 patent drawing
  • US12113916B2 patent drawing

AI summary

Methods and apparatus for hardware based file/document expiry timer enforcement is disclosed. An example method includes instructing, by executing an instruction with a processor, a trusted execution environment to generate an encryption key and a certificate for a document, the certificate including expiry information for the document, the certificate associated with identification information of the document, and the expiry information indicative of a time period for which the encryption key is valid to decrypt the document; encrypting, by executing an instruction with the processor, the document using the encryption key; transmitting the certificate to a first remote network storage device; and transmitting the document to a second remote network storage device.