Automatic Password Escrow for Encrypted Portable Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for data protection, such as encryption and backup, require significant user effort and are often not consistently maintained, leading to inadequate security for sensitive data on personal and corporate systems.

Innovation Solution

A system that automatically encrypts and decrypts data on portable storage devices with minimal user intervention, either by initial password entry or pre-configuration by IT departments, ensuring transparent encryption and decryption processes without repeated password prompts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual encryption and backup methods are used, then data security is improved, but user effort and maintenance burden increase significantly

Engineering Contradiction:
Improvedata securityVSAvoiduser effort
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system enables self-service by having the storage device automatically manage its own encryption and decryption operations. When the device is connected to a computer, it automatically presents encrypted data and handles the decryption process without requiring user intervention, thus improving data security while reducing user effort.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary action by pre-configuring the storage device with encryption capabilities and keys before use. The device is pre-set to automatically encrypt data upon first connection and maintain encryption state throughout subsequent connections, eliminating the need for repeated user actions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If encryption password is required for each connection, then data protection is improved, but operational convenience deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary action by establishing the encryption key and decryption context during the first connection or initial setup. Subsequent connections automatically utilize the pre-established key without requiring re-entry, thus maintaining data protection while significantly improving operational convenience.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by automatically managing the authentication and decryption processes. The storage device presents itself with encrypted data and the computer automatically handles decryption using stored credentials, eliminating the need for repeated user password entry and improving both security and convenience.

Inventive Principle:
Principle #25Self-service

3Reliability

If manual backup processes are implemented, then data reliability is improved, but time consumption and effort increase

Engineering Contradiction:
Improvedata reliabilityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables self-service by having the storage device automatically manage its own data protection and backup operations. The device automatically encrypts data upon connection and maintains reliable storage without requiring manual backup processes, thus improving data reliability while reducing time consumption and user effort.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9715598B2Automatic secure escrowing of a password for encrypted information an attachable storage device
Publication Date: 2017.07.25 INVYSTA TECH GRP
  • US9715598B2 patent drawing
  • US9715598B2 patent drawing
  • US9715598B2 patent drawing

AI summary

External data storage device queries the user for a password on at least the first attachment. The password is escrowed in encrypted form. If the user elects this option, the password is then passed to an encryption module which unlocks the encrypted file or partition and upon subsequent attachments of the external data storage device may automatically unlock the encrypted file or partition using the securely escrowed password. The escrow of the encrypted password is managed in an external storage device containing the encrypted file or partition.