Multi-Level Data Storage for Mobile Device Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In devices configured to store state data encrypted for secure access, the encryption of all data prevents reestablishing a connection between the mobile device and peripheral device, making it incompatible with the Hidden Password feature that bypasses the device password prompt.
Innovation Solution
Implementing a method to store data at distinct security levels within non-volatile memory, where sensitive data like biometric templates are encrypted, and connection information is stored in plain text, allowing for secure authentication and operational mode changes without decrypting all data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If all state data is encrypted for secure access, then security is improved, but the ability to reestablish connections between mobile device and peripheral device is lost
Solution Approach 1:
The patent segments state data into two distinct categories: sensitive data (biometric templates, passwords) stored in an encrypted first portion of non-volatile memory, and connection information stored in a separate unencrypted second portion. This segmentation allows connection reestablishment without decrypting sensitive data, resolving the contradiction between security and operational ease.
Solution Approach 2:
Different portions of the non-volatile memory have different security properties: the first portion is encrypted for high security, while the second portion remains unencrypted for operational accessibility. This local differentiation of security quality enables both secure storage and easy connection reestablishment simultaneously.
2Reliability
If all data is encrypted, then security is improved, but compatibility with Hidden Password feature is lost
Solution Approach 1:
The patent divides encrypted and unencrypted data portions, allowing the Hidden Password feature to access unencrypted connection information while sensitive authentication data remains encrypted. This enables the feature to function without compromising overall security architecture.
Solution Approach 2:
By making only the connection information portion unencrypted while keeping other portions encrypted, the system maintains local quality differences that enable Hidden Password compatibility without undermining the security of sensitive data stored in the encrypted portions.
3Ease of operation
If connection information is stored in plain text, then ease of operation is improved, but security is reduced
Solution Approach 1:
The patent isolates connection information in a separate unencrypted second portion of memory, distinct from the encrypted first portion containing sensitive data. This segmentation minimizes security risk by limiting the scope of unencrypted storage to only non-critical connection data.
Solution Approach 2:
The system applies different security qualities to different data types: connection information receives no encryption (high operational ease, lower security), while biometric templates and passwords receive full encryption (high security, lower operational ease). This localized quality assignment optimizes the overall system by matching security levels to data sensitivity.
Data Source
AI summary
Rather than storing all data in the same manner, e.g., an encrypted manner, a security level with which to associate received data of a given type may be determined. Subsequently, distinct types of data may be stored in a distinct manner, with the manner of storage having a security level appropriate to the type of data. For example, a first type of data may be stored in an encrypted manner (i.e., with a high level of security), while a second level of data may be stored in a plain text manner (i.e., with a low level of security).


