Portable Security Device for On-Device Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing data exchange between user-owned devices and centralized servers or remote devices are inadequate in terms of security and ease of use, as they typically only perform authentication and are vulnerable to malware and key theft.

Innovation Solution

A portable security device equipped with a processing unit, secure element, and cryptographic accelerators that perform on-the-fly encryption and decryption, ensuring secure data exchange by keeping cryptographic keys within the device and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored in user-owned devices, then data exchange functionality is enabled, but security is compromised due to malware and key theft risks

Engineering Contradiction:
ImprovesecurityVSAvoidmalware vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the cryptographic key storage and management functions from the user-owned device (host device) and places them in a separate portable security device. This physical separation ensures that even if the host device is compromised by malware, the cryptographic keys remain protected in the portable device, directly resolving the security vulnerability to malware.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The portable security device acts as an intermediary between the host device and the data exchange process. It holds the cryptographic keys and performs encryption/decryption operations without exposing the keys to the host device's operating system or storage, thereby mediating the security risk while enabling data exchange functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If authentication-only devices are used, then device complexity is reduced, but security functionality is insufficient for protecting stored and transmitted data

Engineering Contradiction:
Improvesecurity functionalityVSAvoiddevice capability
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The portable security device is designed with multi-functionality, serving not only for authentication but also for encrypting data before it is stored on the host device and for decrypting data during retrieval. This universal approach consolidates multiple security functions into a single device, enhancing security functionality without proportionally increasing complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent combines authentication, encryption, and decryption capabilities into a single portable security device. By merging these functions that were previously distributed across multiple systems or software components, the solution achieves comprehensive security functionality while maintaining a unified, manageable device interface.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If cryptographic operations are performed on the host device, then processing speed is improved, but security is compromised due to exposure of keys and operations

Engineering Contradiction:
ImprovesecurityVSAvoidencryption/decryption speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent replaces the software-based cryptographic operations on the host device with hardware-based cryptographic operations in the portable security device. This substitution moves the cryptographic processing to a dedicated security hardware environment, maintaining security while leveraging hardware acceleration for efficient processing.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The portable security device serves as an intermediary processing unit that handles all cryptographic operations. Data is transferred to this secure intermediary for encryption/decryption, which then returns the processed data. This mediates the speed requirement by providing dedicated cryptographic hardware while protecting the host device from security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2902934B1Portable Security Device, Method for Securing a Data Exchange and Computer Program Product
Publication Date: 2019.04.10 NXP BV
  • EP2902934B1 patent drawingFigure 1
  • EP2902934B1 patent drawingFigure 2
  • EP2902934B1 patent drawingFigure 3A

AI summary

There is disclosed a portable security device for securing a data exchange between a host device and a remote device, said portable security device comprising a processing unit, a secure element and a data interface, wherein: the secure element is arranged to store an encryption key and a decryption key; the processing unit is arranged to control the encryption of data to be transmitted from the host device to the remote device, wherein said encryption is performed using said encryption key; the processing unit is further arranged to control the decryption of data transmitted from the remote device to the host device, wherein said decryption is performed using said decryption key. Furthermore, a corresponding method for securing a data exchange between a host device and a remote device using a portable security device is disclosed, as well as a corresponding computer program product.