Hardware-Based File Expiry Timer Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The security of files stored in cloud storage is compromised due to unauthorized access, particularly in sensitive fields like law and medicine, where data protection is critical, and existing solutions fail to effectively manage data security while allowing access from multiple devices.
Innovation Solution
Implementing a hardware-based expiry timer enforcement system using trusted execution environments (TEEs) to generate encryption keys and certificates with expiration information, ensuring secure storage and access by encrypting files and storing them in cloud storage, with only authorized devices able to decrypt based on valid expiry information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If files are stored remotely in cloud storage for multi-device access, then accessibility and convenience are improved, but security and control over data access are worsened
Solution Approach 1:
The system segments the security control mechanism into distributed hardware security modules across multiple trusted devices. Each device maintains its own security context and expiry timer state independently, allowing secure multi-device access without centralizing security control in a single point of failure.
Solution Approach 2:
The patent introduces hardware-based expiry timers as an intermediary mechanism between the cloud storage system and access requests. These timers act as mediators that automatically enforce access policies without requiring continuous human intervention or complex software-based authentication systems.
2Reliability
If hardware-based expiry timers are implemented for automatic access control, then security is improved, but device complexity and implementation difficulty are worsened
Solution Approach 1:
The hardware security modules are designed to autonomously manage their own security state, including automatically tracking expiry timers and enforcing access decisions without requiring external management overhead. This self-service capability reduces the operational complexity despite the hardware complexity.
Solution Approach 2:
The system changes the security enforcement parameter from software-based policy evaluation to hardware-based timer enforcement. This parameter change shifts the complexity from software management to hardware implementation, but provides more reliable and consistent security enforcement.
Data Source
AI summary
Methods and apparatus for hardware based file/document expiry timer enforcement is disclosed. An example method includes instructing, by executing an instruction with a processor, a trusted execution environment to generate an encryption key and a certificate for a document, the certificate including expiry information for the document, the certificate associated with identification information of the document, and the expiry information indicative of a time period for which the encryption key is valid to decrypt the document; encrypting, by executing an instruction with the processor, the document using the encryption key; transmitting the certificate to a first remote network storage device; and transmitting the document to a second remote network storage device.


