Removable Media Encryption Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data encryption methods on removable media do not effectively prevent insider leaks, as authorized users possess decryption keys, allowing unauthorized data release, and prohibiting removable media usage limits information mobility within enterprises.
Innovation Solution
A system that stores and manages encryption keys centrally, ensuring users do not have direct access to keys by generating a unique medium key for each removable medium, which is stored and encrypted, allowing only authorized systems within the enterprise to decrypt data.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If standard encryption methods are used on removable media, then data protection is provided, but insider leaks cannot be prevented because the owner possesses the decryption key
Solution Approach 1:
The patent introduces a key management system as an intermediary between the user and the encryption keys. The system includes a key distribution center that issues keys to users, and a key recovery agent that can retrieve keys if lost. This intermediary structure prevents direct possession of keys by users, thereby preventing insider leaks while maintaining data protection functionality.
Solution Approach 2:
The patent segments the key management function from the data storage function. Instead of storing encryption keys locally with the data on removable media, the system separates key storage in a centralized database and data storage on removable media. This segmentation ensures that even if a user possesses both the data and the key, they cannot leak the information without detection or authorization.
2Reliability
If removable media usage is prohibited to prevent data leaks, then security is improved, but information mobility and productivity are reduced
Solution Approach 1:
The key management system acts as an intermediary that enables secure data mobility. Users can transfer data on removable media without possessing the decryption keys, as the keys are managed centrally. This allows information to move freely within the enterprise while maintaining security, resolving the contradiction between security and productivity.
Solution Approach 2:
The system changes the parameter of key possession from individual user possession to centralized system possession. By altering who holds the keys (from users to a key management system), the system enables both secure data transfer and maintained productivity, as users can still access and transfer data while the system maintains control over encryption keys.
3Ease of operation
If encryption keys are stored on the removable medium with the data, then ease of access is improved, but protection against unauthorized access is reduced
Solution Approach 1:
The patent introduces a key management system as an intermediary that handles key storage separately from data storage. The system includes a database that stores encryption keys and a key recovery mechanism. This intermediary structure maintains ease of access for authorized users while providing strong protection against unauthorized access, as keys are not stored locally with the data.
Solution Approach 2:
The patent extracts the encryption keys from the removable media and stores them in a centralized key management database. This extraction separates the security function from the storage function, ensuring that even if data is copied to removable media, the keys remain protected in a secure centralized location, preventing unauthorized access.
Data Source
AI summary
A method for encrypting and storing data on a removable medium includes: obtaining a medium key uniquely associated with the removable medium; encrypting the data using the medium key to generate encrypted data; and writing the encrypted data onto the removable medium.


