Mobile Storage Encryption Key Management via Internal Extraction
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing memory systems lack versatile content control features, particularly in mobile storage devices, where encryption keys are often stored externally, leading to insecure data access and limited control for content owners.
Innovation Solution
Implementing a memory system where encryption-decryption keys are stored within the mobile storage medium, inaccessible from external devices, and using a tree structure for access control to grant permissions to authorized entities, allowing for secure access and separation of operations between applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If encryption keys are stored externally to the mobile storage medium, then key management is simplified, but security control over content access is lost
Solution Approach 1:
The patent extracts the encryption keys from external storage and embeds them within the mobile storage medium itself, specifically in a secure key storage area that is inaccessible to external devices. This extraction of keys from the external environment eliminates the security vulnerability of external key storage while maintaining secure key management through the medium's internal security architecture.
Solution Approach 2:
The patent implements a nested structure where the encryption keys are stored within the mobile storage medium, which is itself contained within or integrated with the mobile device. The key storage area is nested within the secure element of the medium, creating multiple layers of protection. This nesting ensures that keys remain under the control of the content proprietor while being accessible to authorized devices.
2Reliability
If encryption keys are made inaccessible from external devices, then security is enhanced, but access control versatility is reduced
Solution Approach 1:
The patent introduces an intermediary authentication mechanism that mediates between the inaccessible encryption keys and the need for versatile access control. When a device seeks to access encrypted content, it presents authentication credentials to the mobile storage medium. The medium's authentication module verifies these credentials and, upon successful authentication, provides temporary access to the decryption keys or authorized content. This intermediary authentication layer enables versatile access control policies while maintaining the security of the actual encryption keys.
Solution Approach 2:
The patent implements dynamic access control where the availability of decryption keys is not static but changes based on authentication status and access policies. The system can dynamically grant or revoke access rights, provide different levels of access to different authenticated entities, and manage multiple authentication states. This dynamic behavior enables versatile content control while the keys themselves remain securely stored and inaccessible from external devices.
3Adaptability or versatility
If multiple applications access the mobile storage device simultaneously, then functionality is enhanced, but security breaches and crosstalk between applications may occur
Solution Approach 1:
The patent segments the access control architecture into separate authentication contexts, one for each application or entity. Each authenticated entity receives a unique authentication token or session identifier that is tied to its specific credentials and access rights. The system maintains separate authentication states and access control lists for different entities, preventing one application from accessing another application's authenticated content. This segmentation isolates security contexts and prevents crosstalk between applications while supporting multiple simultaneous accessors.
Data Source
AI summary
Many storage devices are not aware of file systems while many computer host devices read and write data in the form of files. The host device provides a key reference or ID, while the memory system generates a key value in response which is associated with the key ID, which is used as the handle through which the memory retains complete and exclusive control over the generation and use of the key value for cryptographic processes, while the host retains control of files.


