Hardware Data Transfer Device Multi-Key Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data backup solutions that encrypt data prior to storage on removable media often increase backup time and consume valuable computer resources, and security risks remain due to the potential theft of unencrypted data storage devices.
Innovation Solution
A data transfer device that encrypts data using multiple encryption keys, storing each portion of records as separate data blocks with each block encrypted using a unique key, and pads partial blocks with redundant data to maintain data integrity and security, allowing for efficient encryption and decryption within the device without relying on host device resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data are encrypted using software encryption prior to backup, then data security is improved, but backup time increases and computer resources are consumed
Solution Approach 1:
The encryption function is extracted from the host computer's software and transferred to a dedicated hardware data transfer device. This separates the encryption operation from the backup operation, allowing the host to write data without encryption overhead while the dedicated device handles encryption independently, thus resolving the contradiction between security and backup speed
Solution Approach 2:
A dedicated data transfer device acts as an intermediary between the host computer and the removable storage medium. This intermediary performs encryption operations independently, preventing the host system's resources from being consumed by encryption tasks while still providing secure encrypted backups, thereby eliminating the trade-off between security and resource consumption
2Productivity
If data are stored without encryption on removable storage items, then backup speed is improved, but security is compromised due to potential theft
Solution Approach 1:
The encryption function is extracted from the host computer's software and transferred to a dedicated hardware data transfer device. This separates the encryption operation from the backup operation, allowing the host to write data without encryption overhead while the dedicated device handles encryption independently, thus resolving the contradiction between security and backup speed
Solution Approach 2:
The data transfer device autonomously performs encryption operations without requiring host system intervention or resource allocation. The device self-manages the encryption process using its own processing capabilities, enabling fast backup speeds while maintaining security without burdening the host system
3Reliability
If multiple encryption keys are used for different portions of records, then data security is enhanced, but device complexity increases
Solution Approach 1:
The data stream is segmented into distinct portions (first portion and second portion), each encrypted with a different encryption key. This segmentation allows for organized key management where each key protects a specific segment, making the complexity manageable through structured division rather than monolithic key management
Solution Approach 2:
Different encryption keys are applied to different portions of the data records based on local requirements. This allows selective encryption strategies where sensitive portions receive stronger or different encryption than less sensitive portions, optimizing security while managing complexity through localized key application
Data Source
AI summary
A data transfer device for storing data to a removable data storage item, wherein data are received as records and encrypted by the data transfer device prior to storage. The data transfer device encrypts a first portion of the records using a first encryption key and a second portion of the records using a second encryption key. The encrypted records are then stored to the removable data storage item as a plurality of data blocks, each data block comprising one or more encrypted records, wherein records in a respective data block are encrypted using only a respective one of the encryption keys.


