Mobile Storage Encryption Key Management via Internal Extraction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing memory systems lack versatile content control features, particularly in mobile storage devices, where encryption keys are often stored externally, leading to insecure data access and limited control for content owners.

Innovation Solution

Implementing a memory system where encryption-decryption keys are stored within the mobile storage medium, inaccessible from external devices, and using a tree structure for access control to grant permissions to authorized entities, allowing for secure access and separation of operations between applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If encryption keys are stored externally to the mobile storage medium, then key management is simplified, but security control over content access is lost

Engineering Contradiction:
Improvekey managementVSAvoidsecurity control
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the encryption keys from external storage and embeds them within the mobile storage medium itself, specifically in a secure key storage area that is inaccessible to external devices. This extraction of keys from the external environment eliminates the security vulnerability of external key storage while maintaining secure key management through the medium's internal security architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a nested structure where the encryption keys are stored within the mobile storage medium, which is itself contained within or integrated with the mobile device. The key storage area is nested within the secure element of the medium, creating multiple layers of protection. This nesting ensures that keys remain under the control of the content proprietor while being accessible to authorized devices.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If encryption keys are made inaccessible from external devices, then security is enhanced, but access control versatility is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between the inaccessible encryption keys and the need for versatile access control. When a device seeks to access encrypted content, it presents authentication credentials to the mobile storage medium. The medium's authentication module verifies these credentials and, upon successful authentication, provides temporary access to the decryption keys or authorized content. This intermediary authentication layer enables versatile access control policies while maintaining the security of the actual encryption keys.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic access control where the availability of decryption keys is not static but changes based on authentication status and access policies. The system can dynamically grant or revoke access rights, provide different levels of access to different authenticated entities, and manage multiple authentication states. This dynamic behavior enables versatile content control while the keys themselves remain securely stored and inaccessible from external devices.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If multiple applications access the mobile storage device simultaneously, then functionality is enhanced, but security breaches and crosstalk between applications may occur

Engineering Contradiction:
Improvemulti-application supportVSAvoidsecurity breaches and crosstalk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the access control architecture into separate authentication contexts, one for each application or entity. Each authenticated entity receives a unique authentication token or session identifier that is tied to its specific credentials and access rights. The system maintains separate authentication states and access control lists for different entities, preventing one application from accessing another application's authenticated content. This segmentation isolates security contexts and prevents crosstalk between applications while supporting multiple simultaneous accessors.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8504849B2Method for versatile content control
Publication Date: 2013.08.06 SANDISK TECHNOLOGIES LLC
  • US8504849B2 patent drawing
  • US8504849B2 patent drawing
  • US8504849B2 patent drawing

AI summary

Many storage devices are not aware of file systems while many computer host devices read and write data in the form of files. The host device provides a key reference or ID, while the memory system generates a key value in response which is associated with the key ID, which is used as the handle through which the memory retains complete and exclusive control over the generation and use of the key value for cryptographic processes, while the host retains control of files.