Multi-Level Portable Data Storage With Certificate-Gated Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data storage and transfer methods are wasteful, size-limited, and insecure for classified or proprietary data, particularly in multi-level secure environments, with issues such as unencrypted storage, loss of devices, and access to remnant data.
Innovation Solution
A portable data storage device with dual data bus interfaces and a non-volatile memory system using PKI and role-based security, enabling secure access to multiple classified areas through certificates and private keys, allowing read-only or read/write operations based on authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If unencrypted non-volatile data storage devices (USB drives, hard drives) are used for data transfer, then data storage capacity and portability are improved, but security is worsened due to risks of loss, misplacement, theft, and access to remnant data
Solution Approach 1:
The storage device is divided into multiple encrypted storage areas, each protected by a unique private key. This segmentation allows selective access to different data portions based on authentication credentials, ensuring that even if the device is lost or stolen, not all data is compromised.
Solution Approach 2:
A cryptography manager acts as an intermediary between the host device and the storage areas. It manages the encryption/decryption processes and controls access to different storage areas based on authenticated private keys, enabling secure data transfer while maintaining security.
2Reliability
If write-once compact discs are used for data transfer, then security is improved through write-protection, but storage capacity is worsened and the medium is discarded after every use
Solution Approach 1:
Instead of discarding the storage medium after use like write-once CDs, the invention enables repeated use of the same non-volatile storage device across multiple classification levels by authenticating different private keys for different storage areas, thereby recovering and reusing the storage capacity.
Solution Approach 2:
The storage device transitions from a static write-once medium to a dynamic multi-level storage system where access rights change based on authenticated private keys. The same physical device can serve different classification levels dynamically through cryptographic authentication.
3Reliability
If pin code hard drives are used for single classification storage, then security is improved, but versatility is worsened due to limited use across multiple classification levels
Solution Approach 1:
The storage device achieves universality by supporting multiple classification levels (e.g., unclassified, classified, top secret) within a single device. Different storage areas can be accessed by authenticating with different private keys, making the device versatile across multiple security domains.
Solution Approach 2:
The invention adds a cryptographic authentication dimension to traditional physical security methods. Instead of relying solely on physical protection or single-level access controls, the system uses cryptographic keys as an additional dimension of control, enabling multi-level access while maintaining security.
4Adaptability or versatility
If dual data bus interfaces are implemented for read-only and read/write operations, then adaptability is improved, but device complexity increases
Solution Approach 1:
The read-only and read/write capabilities are extracted as separate data bus interfaces. This extraction allows the system to present different interface characteristics to different hosts based on authentication results, improving adaptability while managing complexity through modular interface design.
Data Source
AI summary
A portable data storage device includes a read/write data bus interface and a read only data bus interface to exchange data with a host device. The data storage device includes a non-volatile memory storage having a plurality of data file storage areas. The different storage areas include data files having a classification level. Each data file storage area is associated with a private key and a certificate used to authenticate the host device. The portable data storage device also includes certificate storage area that includes certificates for each data file storage area. A cryptography manager controls access to the data file storage areas through one of the data bus interfaces upon receipt of a private key that matches the certificate for an associated data file storage area.


