Hardware-Locked Encrypted Backup Using PUF Identity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data backup technologies face challenges in securely protecting computer backups due to environmental changes and unauthorized access, particularly in classified environments where chain of custody and policy restrictions complicate the restoration of critical data.

Innovation Solution

The implementation of hardware-locked encrypted backups (HWLE-BU) uses a device's unique hardware identity, derived from a Physically-Unclonable Function (PUF), to cryptographically bind the encryption, allowing only the specific hardware device to decrypt the data, ensuring secure restoration and transfer.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If backups are created with no or limited security protection to avoid restore complications, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A hardware device acts as an intermediary between the backup data and the decryption process. The hardware device securely stores the encryption key and performs decryption operations without exposing the key to IT administrators or users, thus maintaining security while enabling operational access to backups.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces traditional software-based key management systems with a hardware-based security system. The encryption key is stored in secure hardware rather than software, making it inaccessible to administrative processes and eliminating the security risks associated with software key management.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If IT administrators are given access to all keys for backup management, then ease of operation is improved, but security is worsened

Engineering Contradiction:
Improveease of operationVSAvoidunauthorized access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The hardware device serves as an intermediary that mediates between backup management operations and the encryption key. IT administrators can manage backups through normal interfaces, but the hardware device prevents them from accessing the actual encryption keys, thus maintaining operational ease while blocking unauthorized access paths.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If copies of critical data are created for backup purposes, then reliability is improved, but security is worsened due to chain of custody restrictions

Engineering Contradiction:
ImprovereliabilityVSAvoidchain of custody restrictions
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates encrypted copies of critical data for backup purposes. The encryption ensures that while copies exist for reliability and restoration purposes, the actual critical data remains protected. The hardware-locked encryption maintains chain of custody by ensuring that only authorized hardware can access the data copies.

Inventive Principle:
Principle #26Copying

4Reliability

If hardware-locked encrypted backups are implemented using PUF, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The hardware device uses Physically-Unclonable Functions (PUF) to generate and store encryption keys internally without requiring external key management infrastructure. The PUF-based key generation is self-contained within the hardware device, providing high security while avoiding the complexity of external key management systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10437655B2Hardware-locked encrypted backup
Publication Date: 2019.10.08 ANALOG DEVICES INC
  • US10437655B2 patent drawing
  • US10437655B2 patent drawing

AI summary

A hardware-locked encrypted backup (HWLE-BU) that is locked to a single hardware device using the device's unique hardware identity, based on a Physically-Unclonable Function (PUF) or other suitable means providing a unique hardware identity. The HWLE-BU is bound to a specific hardware identity such that only the physical device that created the HWLE-BU can decrypt it, i.e., restoring HWLE-BU data requires utilizing the same physical hardware device in the decryption process.