Cryptographic Key Extraction for Location-Based Data Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory devices lack effective mechanisms to securely manage access to data based on location, requiring physical movement of data in and out of the device when transitioning between secure and non-secure areas, which is inefficient and insecure.

Innovation Solution

Implementing a system where a computing device receives and removes a cryptographic key based on location, using a replay protected memory block (RPMB) to encrypt and decrypt data only when within a designated secure location, eliminating the need for physical data transfer by logically and physically erasing the key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is physically moved in and out of the memory device when transitioning between secure and non-secure areas, then data security is maintained, but system efficiency deteriorates and data handling risks increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the cryptographic key from the memory device when transitioning to non-secure areas, rather than moving the actual data. This is achieved through a controller that monitors location via GPS and automatically removes the decryption key from the RPMB (replay protected memory block) when the device exits a geofenced secure area, thereby maintaining security while avoiding inefficient data transfer operations

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary cryptographic key as a mediator between the secure data and the user. The key acts as a controlled access mechanism that can be selectively present or absent based on location, allowing the system to maintain security policies without physically relocating large amounts of data between secure and non-secure storage locations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is physically moved in and out of the memory device when transitioning between secure and non-secure areas, then data security is maintained, but complexity of data handling increases

Engineering Contradiction:
Improvedata securityVSAvoiddata handling complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of implementing complex physical data movement mechanisms, the patent extracts only the essential cryptographic key from the memory device. This simplifies the data handling process by working with a small, manageable key rather than large datasets, while still achieving the same security objective through cryptographic protection

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses cryptographic copying where the essential security attribute (access rights) is replicated through the cryptographic key rather than physically copying the actual data. The key serves as a digital representation of access permissions that can be efficiently created, stored, and removed without manipulating the underlying secure data

Inventive Principle:
Principle #26Copying

3Reliability

If cryptographic key is removed from the memory device when leaving secure location, then data access security is enhanced, but key management complexity increases

Engineering Contradiction:
Improvedata access securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements self-service key management where the controller automatically performs key removal and restoration operations based on location information from GPS or other location services. The system monitors its own location status and autonomously executes the appropriate key management action without requiring manual user intervention, thereby simplifying the user experience while maintaining security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates feedback mechanisms where the system continuously monitors location data and uses this information to dynamically control the presence of the cryptographic key. The location information feeds back to the key management logic, which automatically adjusts key availability accordingly, creating a closed-loop system that adapts to changing security requirements based on real-time location conditions

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240028747A1Preventing access to data based on locations
Publication Date: 2024.01.25 MICRON TECHNOLOGY INC
  • US20240028747A1 patent drawing
  • US20240028747A1 patent drawing
  • US20240028747A1 patent drawing

AI summary

Data can be stored in a computing device as encrypted to prevent the data from being read and/or modified without being decrypted using cryptographic information. To prevent the data from being decrypted in locations other than a secure location, the cryptographic information can be removed logically and physically from the computing device when it is determined that the computing device has left the secure location.