Online Key Protected Storage Media Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

High-capacity storage devices and virtual storage mediums are vulnerable to data exposure if lost or stolen, leading to user frustration due to the lack of effective protection mechanisms.

Innovation Solution

A method is introduced to create a key protector for storage media using an online key, where a master key for encryption and decryption is encrypted based on the online key, and stored as a key protector, ensuring secure access only through authentication with a remote service.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If data is stored on high-capacity storage devices or virtual storage mediums, then storage capacity is improved, but data security deteriorates due to vulnerability to loss or theft

Engineering Contradiction:
Improvestorage capacityVSAvoiddata security
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The encryption key (master key) is segmented into multiple parts: a device-specific portion stored locally on the storage device and a user-specific portion stored remotely. This segmentation ensures that neither portion alone can decrypt the data, resolving the contradiction by maintaining security while enabling high-capacity storage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A remote service acts as an intermediary between the storage device and the user, managing the user-specific key portion. This intermediary enables secure access control without requiring the full decryption key to be stored on the potentially vulnerable storage device, thus maintaining data security while utilizing high-capacity storage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is implemented on storage media, then data security is improved, but access complexity increases due to key management requirements

Engineering Contradiction:
Improvedata securityVSAvoidkey management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The user-specific key portion is extracted from the storage device and stored remotely in a cloud service. This extraction simplifies the device's key management by removing the need to securely store and manage the complete decryption key locally, reducing device complexity while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system enables self-service authentication where users can recover access to their encrypted storage by authenticating with the remote service using their credentials. This self-service mechanism simplifies access management by eliminating the need for complex manual key recovery procedures, reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

3Speed

If a master key is stored on the storage device for encryption/decryption, then access speed is improved, but security deteriorates due to exposure risk if the device is compromised

Engineering Contradiction:
Improveaccess speedVSAvoidsecurity
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The master key is segmented into a device-specific portion stored locally for fast access and a user-specific portion stored remotely for security. This segmentation enables the device to quickly access its local key portion while the remote portion provides security against device compromise, resolving the contradiction between access speed and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The device-specific key portion is preliminarily prepared and stored on the device before needed for decryption operations. This preliminary action enables fast local decryption while the remote user-specific portion provides the necessary security layer, allowing the device to operate quickly without storing the complete sensitive key material.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8462955B2Key protectors based on online keys
Publication Date: 2013.06.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8462955B2 patent drawing
  • US8462955B2 patent drawing
  • US8462955B2 patent drawing

AI summary

An online key stored by a remote service is generated or otherwise obtained, and a storage media (as it applies to the storage of data on a physical or virtual storage media) master key for encrypting and decrypting a physical or virtual storage media or encrypting and decrypting one or more storage media encryption keys that are used to encrypt a physical or virtual storage media is encrypted based at least in part on the online key. A key protector for the storage media is stored, the key protector including the encrypted master key. The key protector can be subsequently accessed, and the online key obtained from the remote service. The master key is decrypted based on the online key, allowing the one or more storage media encryption keys that are used to decrypt the storage media to be decrypted.