File System Filter Challenge Response Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is a need for a simplified and secure method to prevent unauthorized applications or application launchers on electronic devices from accessing protected content stored on non-volatile semiconductor memory devices, as existing encryption techniques are not sufficient to prevent unauthorized access even if the encryption key is obtained.

Innovation Solution

Implementing a challenge/response authentication mechanism using a file system filter on the host device, which sends a challenge to the software entity, receives a response, calculates a matching response, and allows access only if the responses match, thereby controlling access to protected content on secure removable memory devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If encryption is used to protect content on non-volatile semiconductor memory devices, then content protection is improved, but unauthorized applications can still access the encrypted content if they obtain the encryption key

Engineering Contradiction:
Improvecontent protectionVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

A file system filter is introduced as an intermediary component between the application and the encrypted content on the non-volatile semiconductor memory device. This filter performs challenge/response authentication to verify application authorization before allowing access to the content, even if the application obtains the encryption key. The filter acts as a security gatekeeper that prevents unauthorized access despite the presence of encryption keys in the system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If a file system filter with challenge/response authentication is implemented, then unauthorized access prevention is improved, but device complexity increases

Engineering Contradiction:
Improveunauthorized access preventionVSAvoidauthentication mechanism complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The authentication mechanism performs preliminary verification through challenge/response authentication before granting access to encrypted content. The file system filter issues a challenge to the application, verifies the response against stored credentials, and only then allows access to the content. This preliminary action ensures authorization is confirmed before any sensitive operations occur, preventing unauthorized access while maintaining a manageable complexity through standardized authentication flows.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8443207B2File system filter authentication
Publication Date: 2013.05.14 PALISADE TECH LLP
  • US8443207B2 patent drawing
  • US8443207B2 patent drawing
  • US8443207B2 patent drawing

AI summary

A method of accessing content includes installing a file system filter for a secure removable memory device on a host device. A challenge is sent from the file system filter to a software entity on the host device, and a software entity response is received at the file system filter in response to the challenge. A file system filter response is calculated at the file system filter using the challenge, and access to first content on the secure removable memory device is provided if the software entity response matches the file system filter response.