Cryptographic Key Extraction for Location-Based Data Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory devices lack effective mechanisms to securely manage access to data based on location, requiring physical movement of data in and out of the device when transitioning between secure and non-secure areas, which is inefficient and insecure.
Innovation Solution
Implementing a system where a computing device receives and removes a cryptographic key based on location, using a replay protected memory block (RPMB) to encrypt and decrypt data only when within a designated secure location, eliminating the need for physical data transfer by logically and physically erasing the key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data is physically moved in and out of the memory device when transitioning between secure and non-secure areas, then data security is maintained, but system efficiency deteriorates and data handling risks increase
Solution Approach 1:
The patent extracts the cryptographic key from the memory device when transitioning to non-secure areas, rather than moving the actual data. This is achieved through a controller that monitors location via GPS and automatically removes the decryption key from the RPMB (replay protected memory block) when the device exits a geofenced secure area, thereby maintaining security while avoiding inefficient data transfer operations
Solution Approach 2:
The patent introduces an intermediary cryptographic key as a mediator between the secure data and the user. The key acts as a controlled access mechanism that can be selectively present or absent based on location, allowing the system to maintain security policies without physically relocating large amounts of data between secure and non-secure storage locations
2Reliability
If data is physically moved in and out of the memory device when transitioning between secure and non-secure areas, then data security is maintained, but complexity of data handling increases
Solution Approach 1:
Instead of implementing complex physical data movement mechanisms, the patent extracts only the essential cryptographic key from the memory device. This simplifies the data handling process by working with a small, manageable key rather than large datasets, while still achieving the same security objective through cryptographic protection
Solution Approach 2:
The patent uses cryptographic copying where the essential security attribute (access rights) is replicated through the cryptographic key rather than physically copying the actual data. The key serves as a digital representation of access permissions that can be efficiently created, stored, and removed without manipulating the underlying secure data
3Reliability
If cryptographic key is removed from the memory device when leaving secure location, then data access security is enhanced, but key management complexity increases
Solution Approach 1:
The system implements self-service key management where the controller automatically performs key removal and restoration operations based on location information from GPS or other location services. The system monitors its own location status and autonomously executes the appropriate key management action without requiring manual user intervention, thereby simplifying the user experience while maintaining security
Solution Approach 2:
The patent incorporates feedback mechanisms where the system continuously monitors location data and uses this information to dynamically control the presence of the cryptographic key. The location information feeds back to the key management logic, which automatically adjusts key availability accordingly, creating a closed-loop system that adapts to changing security requirements based on real-time location conditions
Data Source
AI summary
Data can be stored in a computing device as encrypted to prevent the data from being read and/or modified without being decrypted using cryptographic information. To prevent the data from being decrypted in locations other than a secure location, the cryptographic information can be removed logically and physically from the computing device when it is determined that the computing device has left the secure location.


