Hardened Remote Storage for Private Cryptography Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication systems that rely on locally stored private cryptography keys are vulnerable to misappropriation due to continuous connectivity with public networks, lacking real-time tamper detection and response mechanisms.

Innovation Solution

A hardened remote storage device that automatically deletes private cryptography keys from memory in response to tamper-related signals, using sensors and processors to ensure real-time security and minimize exposure to unauthorized access, while only making keys available to computing nodes during authentication processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If private cryptography keys are stored locally on the computing device, then authentication can be performed efficiently, but the keys become vulnerable to misappropriation due to continuous network connectivity

Engineering Contradiction:
Improveauthentication efficiencyVSAvoidkey security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent extracts the private cryptography keys from the computing device and stores them in a separate, hardened remote storage device. This physical separation removes the vulnerability of having keys stored locally on devices that are continuously connected to public networks, while still allowing the computing device to access keys for authentication purposes through secure communication channels.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a hardened remote storage device as an intermediary between the computing device and the private cryptography keys. This intermediary provides a secure location for key storage that is physically separated from the computing device, while still enabling authenticated access when needed, thus resolving the contradiction between accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a password-protected file stores private keys locally, then key protection is provided, but real-time tamper detection and response is not available

Engineering Contradiction:
Improvekey protectionVSAvoidtamper detection capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements preliminary protective measures by storing private keys in a hardened remote storage device that is physically separated from the computing device. This preliminary action prevents tamperers from accessing keys even if they compromise the computing device, as the keys reside in a secure, isolated environment that is difficult to penetrate.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates tamper detection mechanisms that provide feedback about security breaches. When tampering is detected in the hardened storage device, the system can respond by deleting compromised keys or alerting the user, enabling real-time detection and response to security threats that would be impossible with simple local file storage.

Inventive Principle:
Principle #23Feedback

3Reliability

If private keys are stored externally in a hardened device, then tamper-responsiveness is achieved, but device complexity increases

Engineering Contradiction:
Improvetamper-responsivenessVSAvoidstorage system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication system into two distinct components: a hardened remote storage device that holds private keys and a computing device that performs authentication operations. This segmentation allows each component to be optimized independently - the storage device for security and tamper-responsiveness, and the computing device for authentication functionality - while reducing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10116633B2Systems and devices for hardened remote storage of private cryptography keys used for authentication
Publication Date: 2018.10.30 BANK OF AMERICA CORP
  • US10116633B2 patent drawing
  • US10116633B2 patent drawing
  • US10116633B2 patent drawing

AI summary

The invention provides for systems and devices for hardened remote storage of private cryptography keys used for authentication. The storage device is tamper-responsive, such that receipt of a signal that indicates physical or non-physical tampering with the storage device or its components results in deletion of the private cryptography key(s) from the memory. The storage device is configured to be separate and remote from a computing node that executes an authentication routine requiring the private cryptography key(s) and, as such, the private cryptography key(s) are accessible to, but not communicated to, the computing node only when the computing node is executing the authentication routine.