Partitioned Computing Device with Key Escrow and Audit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing device architectures fail to balance public and personal security needs by not providing secure access to authorized external entities while protecting sensitive data from malware and law enforcement access, and lack a key escrow system that informs users of potential message exposure.

Innovation Solution

A computing device with multiple partitions: a Malware Protected Partition for secure application execution and an Access Protected Partition for authorized external access, along with a key escrow system that allows users to be informed of potential message exposure, ensuring secure data protection and compliance with legal access requirements.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single partition system is used for executing applications, then device complexity is reduced, but security protection against malware and unauthorized access deteriorates

Engineering Contradiction:
Improvepartition structureVSAvoidsecurity protection
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system divides the computing device into multiple isolated partitions: a first partition for general application execution and a second partition for protected application execution. This segmentation allows different security levels coexist, with the second partition providing malware protection while the first partition maintains ease of operation. The segmentation principle resolves the contradiction by creating structural complexity that enables enhanced security without significantly impacting overall device usability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a protection module as an intermediary between the partitions and external access entities. This intermediary enforces access control policies, allowing authorized external entities to access the first partition while blocking access to the second partition. The intermediary mechanism enables selective access control that balances security requirements with operational needs without requiring complete system isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If authorized external access is permitted to all partitions, then ease of operation for external entities is improved, but security protection of sensitive data deteriorates

Engineering Contradiction:
Improveexternal accessVSAvoiddata protection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments external access permissions by partition, allowing the first partition to accept authorized external access for ease of operation while the second partition remains isolated for data protection. This selective segmentation enables different access policies for different functional areas, resolving the contradiction between operational accessibility and security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different access control qualities to different partitions: the first partition has permissive access control for authorized external entities, while the second partition has restrictive access control. This local differentiation of security properties allows the system to optimize for ease of operation where needed while maintaining strong data protection where required, without applying a uniform security policy that would compromise either goal.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If protected data is made accessible to authorized external entities, then ease of operation is improved, but security protection against unauthorized access deteriorates

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system segments data accessibility by partitioning data storage and execution environments. Protected data resides in the second partition which is isolated from external access, while non-sensitive operations occur in the first partition that accepts external access. This spatial segmentation of data based on sensitivity levels enables selective accessibility that balances operational convenience with security protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The protection module acts as an intermediary that mediates between external entities and partitioned data. It enforces access control policies that allow authorized external entities to access the first partition while blocking access to the second partition containing protected data. This intermediary mechanism enables controlled data accessibility that reduces unauthorized access risk while maintaining operational ease for legitimate operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Reliability

If key escrow system is implemented without user notification, then public security access is improved, but user awareness of message exposure deteriorates

Engineering Contradiction:
Improvepublic security accessVSAvoiduser awareness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements a feedback mechanism where the key escrow system notifies users when their messages are being accessed by external entities. This feedback loop maintains user awareness of message exposure while still allowing public security access to function. The notification mechanism resolves the contradiction by providing information flow that keeps users informed without blocking the key escrow access functionality.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11212095B2Allowing restricted external access to devices
Publication Date: 2021.12.28 BRICKELL CRYPTOLOGY LLC
  • US11212095B2 patent drawing
  • US11212095B2 patent drawing
  • US11212095B2 patent drawing

AI summary

Methods and apparatus for auditing uses of cryptographic keys. In a method embodiment of the present invention, a set of audited uses for a cryptographic key is defined; the key is generated inside a protected execution environment of a digital computer; all software and firmware that is usable in the execution environment to access the key is demonstrated to an auditor; and, for each audited use of the key, a non-tamperable audit record describing said use is released.