Hardware-Locked Encrypted Backup Using PUF Identity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data backup technologies face challenges in securely protecting computer backups due to environmental changes and unauthorized access, particularly in classified environments where chain of custody and policy restrictions complicate the restoration of critical data.
Innovation Solution
The implementation of hardware-locked encrypted backups (HWLE-BU) uses a device's unique hardware identity, derived from a Physically-Unclonable Function (PUF), to cryptographically bind the encryption, allowing only the specific hardware device to decrypt the data, ensuring secure restoration and transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If backups are created with no or limited security protection to avoid restore complications, then ease of operation is improved, but security is worsened
Solution Approach 1:
A hardware device acts as an intermediary between the backup data and the decryption process. The hardware device securely stores the encryption key and performs decryption operations without exposing the key to IT administrators or users, thus maintaining security while enabling operational access to backups.
Solution Approach 2:
The patent replaces traditional software-based key management systems with a hardware-based security system. The encryption key is stored in secure hardware rather than software, making it inaccessible to administrative processes and eliminating the security risks associated with software key management.
2Ease of operation
If IT administrators are given access to all keys for backup management, then ease of operation is improved, but security is worsened
Solution Approach 1:
The hardware device serves as an intermediary that mediates between backup management operations and the encryption key. IT administrators can manage backups through normal interfaces, but the hardware device prevents them from accessing the actual encryption keys, thus maintaining operational ease while blocking unauthorized access paths.
3Reliability
If copies of critical data are created for backup purposes, then reliability is improved, but security is worsened due to chain of custody restrictions
Solution Approach 1:
The patent creates encrypted copies of critical data for backup purposes. The encryption ensures that while copies exist for reliability and restoration purposes, the actual critical data remains protected. The hardware-locked encryption maintains chain of custody by ensuring that only authorized hardware can access the data copies.
4Reliability
If hardware-locked encrypted backups are implemented using PUF, then security is improved, but device complexity is worsened
Solution Approach 1:
The hardware device uses Physically-Unclonable Functions (PUF) to generate and store encryption keys internally without requiring external key management infrastructure. The PUF-based key generation is self-contained within the hardware device, providing high security while avoiding the complexity of external key management systems.
Data Source
AI summary
A hardware-locked encrypted backup (HWLE-BU) that is locked to a single hardware device using the device's unique hardware identity, based on a Physically-Unclonable Function (PUF) or other suitable means providing a unique hardware identity. The HWLE-BU is bound to a specific hardware identity such that only the physical device that created the HWLE-BU can decrypt it, i.e., restoring HWLE-BU data requires utilizing the same physical hardware device in the decryption process.

