Key Escrow Mechanism for Mobile Data Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional cryptography solutions fail to adequately address data security and integrity for mobile devices and removable media, as they are vulnerable to theft, lack robust key management, and require significant computational resources, making them unsuitable for mobile devices with limited processing power and battery life.
Innovation Solution
A method for decrypting data on removable media using a unique user identifier, unique device identifier, and administrator credentials, which involves a key escrow mechanism that securely stores and retrieves cryptography keys, allowing authorized access even when the original device or user credentials are lost.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional cryptography solutions are used for mobile devices, then data security is improved, but computational resource consumption increases and battery life decreases
Solution Approach 1:
The system segments cryptographic operations by separating key generation, key escrow, and decryption functions across different components (mobile device, escrow server, authentication server). This allows mobile devices to perform only lightweight operations while heavier computational tasks are offloaded to servers, reducing battery consumption while maintaining security.
Solution Approach 2:
The patent introduces an escrow server as an intermediary that holds cryptographic keys and performs decryption operations. The mobile device communicates with this intermediary rather than performing all cryptographic operations locally, thereby reducing computational burden and energy consumption on mobile devices while maintaining data security through the intermediary's secure key management.
2Reliability
If public key infrastructure is implemented for key management, then data recoverability is improved, but device complexity and computational requirements increase
Solution Approach 1:
The patent extracts the complex key management and escrow functions from the mobile device and places them on external servers. The mobile device retains only essential cryptographic operations, while the escrow server handles key storage, retrieval, and decryption, thereby reducing device complexity while improving data recoverability through centralized key management.
Solution Approach 2:
The escrow server provides multiple functions including key generation, key escrow, key retrieval, and decryption operations within a single system. This universal approach consolidates what would otherwise require multiple separate components on the mobile device, reducing overall system complexity while maintaining comprehensive data recoverability.
3Reliability
If manual key escrow mechanisms are used, then data access control is improved, but operational efficiency and scalability decrease
Solution Approach 1:
The system implements automated key management where the escrow server automatically generates keys, stores them securely, and retrieves them based on authentication credentials without requiring manual intervention. This self-service approach maintains strict access control while dramatically improving operational efficiency and enabling scalable deployment across multiple devices and users.
Solution Approach 2:
The patent implements automated authentication and key retrieval mechanisms where the system automatically verifies credentials and provides appropriate access based on predefined policies. This feedback loop between authentication and key retrieval eliminates manual processes, maintaining security control while improving operational speed and scalability.
4Reliability
If multiple encryption keys are used for different data files, then data security is improved, but key management difficulty increases
Solution Approach 1:
The patent merges multiple individual key management operations into a unified escrow system. Instead of managing separate keys for each file independently, the system combines all key management functions (generation, storage, retrieval, rotation) into a single centralized escrow server that handles multiple keys and files systematically, thereby maintaining security while dramatically simplifying key management operations.
Data Source
AI summary
A technique that decrypts data stored on removable media, if the device on which the encryption was performed is lost, unavailable, or the user credentials are lost. In example embodiment, this is achieved by using the administrator UID, the administrator UDID, the removable media, the names of one or more data files to be decrypted, the administrator Pswd, and a KeyID to decrypt data stored on the removable media associated with a lost or unavailable mobile device on which encryption was performed.


