Multi-Level Portable Data Storage With Certificate-Gated Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data storage and transfer methods are wasteful, size-limited, and insecure for classified or proprietary data, particularly in multi-level secure environments, with issues such as unencrypted storage, loss of devices, and access to remnant data.

Innovation Solution

A portable data storage device with dual data bus interfaces and a non-volatile memory system using PKI and role-based security, enabling secure access to multiple classified areas through certificates and private keys, allowing read-only or read/write operations based on authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If unencrypted non-volatile data storage devices (USB drives, hard drives) are used for data transfer, then data storage capacity and portability are improved, but security is worsened due to risks of loss, misplacement, theft, and access to remnant data

Engineering Contradiction:
Improvedata storage capacityVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The storage device is divided into multiple encrypted storage areas, each protected by a unique private key. This segmentation allows selective access to different data portions based on authentication credentials, ensuring that even if the device is lost or stolen, not all data is compromised.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A cryptography manager acts as an intermediary between the host device and the storage areas. It manages the encryption/decryption processes and controls access to different storage areas based on authenticated private keys, enabling secure data transfer while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If write-once compact discs are used for data transfer, then security is improved through write-protection, but storage capacity is worsened and the medium is discarded after every use

Engineering Contradiction:
ImprovesecurityVSAvoiddata storage capacity
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

Instead of discarding the storage medium after use like write-once CDs, the invention enables repeated use of the same non-volatile storage device across multiple classification levels by authenticating different private keys for different storage areas, thereby recovering and reusing the storage capacity.

Inventive Principle:
Principle #34Discarding and recovering

Solution Approach 2:

The storage device transitions from a static write-once medium to a dynamic multi-level storage system where access rights change based on authenticated private keys. The same physical device can serve different classification levels dynamically through cryptographic authentication.

Inventive Principle:
Principle #15Dynamics

3Reliability

If pin code hard drives are used for single classification storage, then security is improved, but versatility is worsened due to limited use across multiple classification levels

Engineering Contradiction:
ImprovesecurityVSAvoidmulti-level access capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The storage device achieves universality by supporting multiple classification levels (e.g., unclassified, classified, top secret) within a single device. Different storage areas can be accessed by authenticating with different private keys, making the device versatile across multiple security domains.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The invention adds a cryptographic authentication dimension to traditional physical security methods. Instead of relying solely on physical protection or single-level access controls, the system uses cryptographic keys as an additional dimension of control, enabling multi-level access while maintaining security.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Adaptability or versatility

If dual data bus interfaces are implemented for read-only and read/write operations, then adaptability is improved, but device complexity increases

Engineering Contradiction:
Improveinterface compatibilityVSAvoiddata bus interface structure
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The read-only and read/write capabilities are extracted as separate data bus interfaces. This extraction allows the system to present different interface characteristics to different hosts based on authentication results, improving adaptability while managing complexity through modular interface design.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250306775A1Methods and device for multi-level portable secure data storage
Publication Date: 2025.10.02 ROCKWELL COLLINS INC
  • US20250306775A1 patent drawing
  • US20250306775A1 patent drawing
  • US20250306775A1 patent drawing

AI summary

A portable data storage device includes a read/write data bus interface and a read only data bus interface to exchange data with a host device. The data storage device includes a non-volatile memory storage having a plurality of data file storage areas. The different storage areas include data files having a classification level. Each data file storage area is associated with a private key and a certificate used to authenticate the host device. The portable data storage device also includes certificate storage area that includes certificates for each data file storage area. A cryptography manager controls access to the data file storage areas through one of the data bus interfaces upon receipt of a private key that matches the certificate for an associated data file storage area.