Key Escrow Mechanism for Mobile Data Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional cryptography solutions fail to adequately address data security and integrity for mobile devices and removable media, as they are vulnerable to theft, lack robust key management, and require significant computational resources, making them unsuitable for mobile devices with limited processing power and battery life.

Innovation Solution

A method for decrypting data on removable media using a unique user identifier, unique device identifier, and administrator credentials, which involves a key escrow mechanism that securely stores and retrieves cryptography keys, allowing authorized access even when the original device or user credentials are lost.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional cryptography solutions are used for mobile devices, then data security is improved, but computational resource consumption increases and battery life decreases

Engineering Contradiction:
Improvedata securityVSAvoidbattery consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments cryptographic operations by separating key generation, key escrow, and decryption functions across different components (mobile device, escrow server, authentication server). This allows mobile devices to perform only lightweight operations while heavier computational tasks are offloaded to servers, reducing battery consumption while maintaining security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an escrow server as an intermediary that holds cryptographic keys and performs decryption operations. The mobile device communicates with this intermediary rather than performing all cryptographic operations locally, thereby reducing computational burden and energy consumption on mobile devices while maintaining data security through the intermediary's secure key management.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If public key infrastructure is implemented for key management, then data recoverability is improved, but device complexity and computational requirements increase

Engineering Contradiction:
Improvedata recoverabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the complex key management and escrow functions from the mobile device and places them on external servers. The mobile device retains only essential cryptographic operations, while the escrow server handles key storage, retrieval, and decryption, thereby reducing device complexity while improving data recoverability through centralized key management.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The escrow server provides multiple functions including key generation, key escrow, key retrieval, and decryption operations within a single system. This universal approach consolidates what would otherwise require multiple separate components on the mobile device, reducing overall system complexity while maintaining comprehensive data recoverability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual key escrow mechanisms are used, then data access control is improved, but operational efficiency and scalability decrease

Engineering Contradiction:
Improveaccess controlVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements automated key management where the escrow server automatically generates keys, stores them securely, and retrieves them based on authentication credentials without requiring manual intervention. This self-service approach maintains strict access control while dramatically improving operational efficiency and enabling scalable deployment across multiple devices and users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements automated authentication and key retrieval mechanisms where the system automatically verifies credentials and provides appropriate access based on predefined policies. This feedback loop between authentication and key retrieval eliminates manual processes, maintaining security control while improving operational speed and scalability.

Inventive Principle:
Principle #23Feedback

4Reliability

If multiple encryption keys are used for different data files, then data security is improved, but key management difficulty increases

Engineering Contradiction:
Improvedata securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges multiple individual key management operations into a unified escrow system. Instead of managing separate keys for each file independently, the system combines all key management functions (generation, storage, retrieval, rotation) into a single centralized escrow server that handles multiple keys and files systematically, thereby maintaining security while dramatically simplifying key management operations.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7970142B2System, method and apparatus for decrypting data stored on removable media
Publication Date: 2011.06.28 MARQETA INC
  • US7970142B2 patent drawing
  • US7970142B2 patent drawing
  • US7970142B2 patent drawing

AI summary

A technique that decrypts data stored on removable media, if the device on which the encryption was performed is lost, unavailable, or the user credentials are lost. In example embodiment, this is achieved by using the administrator UID, the administrator UDID, the removable media, the names of one or more data files to be decrypted, the administrator Pswd, and a KeyID to decrypt data stored on the removable media associated with a lost or unavailable mobile device on which encryption was performed.