Partitioned Computing Device with Key Escrow and Audit
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing device architectures fail to balance public and personal security needs by not providing secure access to authorized external entities while protecting sensitive data from malware and law enforcement access, and lack a key escrow system that informs users of potential message exposure.
Innovation Solution
A computing device with multiple partitions: a Malware Protected Partition for secure application execution and an Access Protected Partition for authorized external access, along with a key escrow system that allows users to be informed of potential message exposure, ensuring secure data protection and compliance with legal access requirements.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single partition system is used for executing applications, then device complexity is reduced, but security protection against malware and unauthorized access deteriorates
Solution Approach 1:
The system divides the computing device into multiple isolated partitions: a first partition for general application execution and a second partition for protected application execution. This segmentation allows different security levels coexist, with the second partition providing malware protection while the first partition maintains ease of operation. The segmentation principle resolves the contradiction by creating structural complexity that enables enhanced security without significantly impacting overall device usability.
Solution Approach 2:
The patent introduces a protection module as an intermediary between the partitions and external access entities. This intermediary enforces access control policies, allowing authorized external entities to access the first partition while blocking access to the second partition. The intermediary mechanism enables selective access control that balances security requirements with operational needs without requiring complete system isolation.
2Ease of operation
If authorized external access is permitted to all partitions, then ease of operation for external entities is improved, but security protection of sensitive data deteriorates
Solution Approach 1:
The system segments external access permissions by partition, allowing the first partition to accept authorized external access for ease of operation while the second partition remains isolated for data protection. This selective segmentation enables different access policies for different functional areas, resolving the contradiction between operational accessibility and security protection.
Solution Approach 2:
The patent applies different access control qualities to different partitions: the first partition has permissive access control for authorized external entities, while the second partition has restrictive access control. This local differentiation of security properties allows the system to optimize for ease of operation where needed while maintaining strong data protection where required, without applying a uniform security policy that would compromise either goal.
3Ease of operation
If protected data is made accessible to authorized external entities, then ease of operation is improved, but security protection against unauthorized access deteriorates
Solution Approach 1:
The system segments data accessibility by partitioning data storage and execution environments. Protected data resides in the second partition which is isolated from external access, while non-sensitive operations occur in the first partition that accepts external access. This spatial segmentation of data based on sensitivity levels enables selective accessibility that balances operational convenience with security protection.
Solution Approach 2:
The protection module acts as an intermediary that mediates between external entities and partitioned data. It enforces access control policies that allow authorized external entities to access the first partition while blocking access to the second partition containing protected data. This intermediary mechanism enables controlled data accessibility that reduces unauthorized access risk while maintaining operational ease for legitimate operations.
4Reliability
If key escrow system is implemented without user notification, then public security access is improved, but user awareness of message exposure deteriorates
Solution Approach 1:
The patent implements a feedback mechanism where the key escrow system notifies users when their messages are being accessed by external entities. This feedback loop maintains user awareness of message exposure while still allowing public security access to function. The notification mechanism resolves the contradiction by providing information flow that keeps users informed without blocking the key escrow access functionality.
Data Source
AI summary
Methods and apparatus for auditing uses of cryptographic keys. In a method embodiment of the present invention, a set of audited uses for a cryptographic key is defined; the key is generated inside a protected execution environment of a digital computer; all software and firmware that is usable in the execution environment to access the key is demonstrated to an auditor; and, for each audited use of the key, a non-tamperable audit record describing said use is released.


