Master Passphrase Key Hierarchical Encryption for Multi-Device Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing electronic devices with multiple storage devices face challenges in securely unlocking and managing access to these devices without requiring users to remember and enter multiple passwords, especially in scenarios involving multiple users sharing the same device.
Innovation Solution
A computing system employs a hierarchical encryption scheme using a symmetrically encrypted master passphrase key, derived from authentication information such as a user password or biometric data, to transparently unlock multiple self-encrypting storage devices, allowing access without the need for multiple password entries.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple storage devices are unlocked at boot time using individual passphrase keys, then security is maintained for each device, but users must remember and enter multiple passwords which reduces ease of operation
Solution Approach 1:
The patent combines multiple individual passphrase keys into a single master passphrase key that can unlock all storage devices. The master passphrase key is derived from authentication information and used to symmetrically encrypt and manage access to multiple passphrase keys, allowing users to access multiple devices with a single password rather than remembering multiple individual passwords.
Solution Approach 2:
The master passphrase key serves multiple functions: it can be used to unlock any of the multiple storage devices associated with the electronic device. This universal key provides multi-functionality by replacing the need for device-specific passphrase keys, allowing a single authentication credential to access multiple devices.
2Ease of operation
If a master passphrase key is used to encrypt multiple passphrase keys, then ease of operation improves by using a single password, but system complexity increases due to hierarchical encryption scheme
Solution Approach 1:
The encryption system is segmented into hierarchical levels: the master passphrase key at the top level, and individual passphrase keys for each storage device at lower levels. This segmentation allows the complex encryption operations to be organized in a structured manner, where the master key manages multiple subordinate keys, making the system more manageable despite its complexity.
Solution Approach 2:
The master passphrase key acts as an intermediary between the user's authentication information and the individual storage device passphrase keys. It serves as a mediator that translates a single user password into multiple device-specific access credentials, simplifying the user interaction while managing the underlying complexity through this intermediate layer.
3Speed
If symmetric encryption is used for the master passphrase key, then encryption speed improves, but security may be reduced compared to asymmetric encryption
Solution Approach 1:
The system changes the parameter of encryption type from asymmetric to symmetric encryption for the master passphrase key. This parameter change prioritizes encryption speed over the maximum security level provided by asymmetric encryption, accepting a trade-off where symmetric encryption is used for performance-critical operations while maintaining adequate security through proper key management.
Data Source
AI summary
Examples disclosed herein relate to symmetrically encrypting a master passphrase key. In one implementation, a computing system includes a machine-readable storage medium to store a symmetrically encrypted master passphrase key, an encrypted version of a first passphrase key associated with a second machine-readable storage medium encrypted using the master passphrase key, and an encrypted version of a second passphrase key associated with a third machine-readable storage medium encrypted using the passphrase key. A processing resource may symmetrically encrypt the master passphrase key using an encryption key derived from authentication information and/or decrypt the stored master passphrase key using a decryption key derived from the authentication information.


