Physical Security Device for Embedded Data Key Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security techniques for data processing systems, especially in smaller or cost-sensitive applications, incur high costs and complexity due to the need for dedicated external server systems, making it challenging to balance security and cost effectively.

Innovation Solution

A user-removable physical security device (PSD) is used, uniquely paired with the computerized system, storing cryptographically secured data for performing protected functions, such as decrypting encryption keys, which acts as a higher barrier for unauthorized access by requiring physical possession and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If dedicated external server systems are used for data security, then security is improved, but device complexity and cost increase

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the key management functionality from the main storage system and places it on a separate removable physical security device. This allows the main system to benefit from enhanced security without permanently integrating complex key management infrastructure, thereby reducing overall system complexity while maintaining security improvements.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The removable physical security device acts as an intermediary between the user and the encrypted data. It holds the decryption keys and mediates access by requiring authentication and physical possession, thereby providing security without requiring the main system to contain built-in key management complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated external server systems are used for data security, then security is improved, but cost increases

Engineering Contradiction:
Improvedata securityVSAvoidcost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent employs a removable physical security device that can be lost, damaged, or replaced without requiring expensive recovery procedures. The device serves its security function and can be discarded or replaced if compromised, avoiding the high costs associated with recovering from security breaches in traditional server-based systems.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

By extracting key management to a separate inexpensive removable device, the patent avoids the high cost of dedicated security servers while maintaining security functionality. The removable device can be a simple USB-style device rather than expensive infrastructure.

Inventive Principle:
Principle #2Taking out (Extraction)

3Device complexity

If key management functionality is integrated on production servers, then system complexity is reduced, but security is weakened

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent extracts key management functionality from production servers and places it on removable physical security devices. This separation maintains security by isolating keys from the main system while keeping the server architecture simple, as the servers only need to handle encrypted data without built-in key management complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS8751827B1Apparatus for controlling embedded security on a storage platform
Publication Date: 2014.06.10 EMC IP HLDG CO LLC
  • US8751827B1 patent drawing
  • US8751827B1 patent drawing
  • US8751827B1 patent drawing

AI summary

A method of securely operating a computerized system includes forming a connection to a user-removable physical security device (PSD) which is uniquely paired with the computerized system and which stories cryptographically secured data required for performing a protected function on the computerized system. The PSD may be realized as a USB or similar peripheral device containing security-related data and potentially security processing capability as well. The protected function could be decrypting of encrypted data encryption keys used to encrypt/decrypt user data for example. A user who has an established association with the PSD (e.g. by some preceding registration process) is authenticated, resulting in activation of the PSD on the computerized system. Upon such activation of the PSD, the computerized system engages in a security operation using the cryptographically secured data from the PSD to enable the protected function to be performed under control of the user on the computerized system.