HSM Encryption Key Backup Automation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users often forget to back up the encryption key in hardware security modules (HSMs) when enabling the TPM function, leading to decryption issues upon TPM replacement.

Innovation Solution

An information processing apparatus with a hardware security module (HSM) that automatically checks if the encryption key has been backed up before enabling the HSM function, prompting the user to back it up if not already done, ensuring the key is securely stored before enabling the function.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the TPM function is enabled without mandatory backup, then the enabling process is simple and quick, but the user may forget to back up the encryption key, leading to data loss upon TPM replacement

Engineering Contradiction:
Improveease of enabling TPM functionVSAvoidreliability of encryption key backup
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary action by automatically backing up the encryption key to external storage before the TPM function is enabled. This ensures the backup is completed proactively, eliminating the risk of user forgetfulness while maintaining a simple user interface for enabling the TPM function.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service by automatically handling the encryption key backup process without requiring explicit user intervention. The apparatus autonomously detects when TPM is enabled, initiates the backup process, and manages the external storage connection, freeing the user from manual backup tasks.

Inventive Principle:
Principle #25Self-service

2Reliability

If automatic backup is performed when enabling HSM function, then the encryption key backup reliability is improved, but the system complexity increases due to additional backup process integration

Engineering Contradiction:
Improvereliability of encryption key backupVSAvoidcomplexity of enabling process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges the TPM enabling process with the encryption key backup process into a single integrated operation. When the user enables the TPM function, the system automatically combines this with initiating the backup process to external storage, achieving reliable backup without requiring separate user actions or complex manual procedures.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system autonomously manages the backup process by automatically detecting TPM enablement, preparing the backup, and executing the transfer to external storage without requiring the user to understand or manage the complexity of the backup mechanism.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If manual backup is required, then the user has control over the backup process, but the user may neglect to back up the key, resulting in inability to decrypt confidential data after TPM replacement

Engineering Contradiction:
Improveuser control over backup processVSAvoidloss of encryption key
Core Design Contradiction:
Adaptability or versatilityVSLoss of information

Solution Approach 1:

The system performs preliminary action by automatically executing the encryption key backup before the TPM function becomes active. This proactive approach ensures the key is secured externally before any potential TPM failure, preventing information loss while maintaining user control through the simple enablement interface.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides self-service by automatically handling the entire backup process including detecting TPM enablement, preparing the encryption key, and transferring it to external storage. This eliminates the risk of user neglect while preserving user control through the straightforward TPM enablement action.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10628333B2Information processing apparatus, method of controlling the same, and storage medium
Publication Date: 2020.04.21 CANON KK
  • US10628333B2 patent drawing
  • US10628333B2 patent drawing
  • US10628333B2 patent drawing

AI summary

In an information processing apparatus having a hardware security module (HSM), an HSM function that makes it possible to encrypt and decrypt data using the encryption key of the HSM is able to be set to be enabled under the condition that the encryption key of the HSM is able to be backed up.