Removable Storage Encryption Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Unauthorized access and data theft risks arise from the use of removable storage media, as malicious individuals can smuggle such media into secure sites to cause harm or steal sensitive information, despite organizational policies prohibiting their use.
Innovation Solution
Implementing a secure storage medium managed by a controller that uses multiple encryption keys for accessing and protecting information on removable storage media, allowing site-wide and group-specific access control, ensuring that data encrypted with specific keys can only be accessed by authorized personnel within the designated site or group.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If removable storage media are allowed for use, then data accessibility and convenience are improved, but security risks and unauthorized access increase
Solution Approach 1:
The patent applies parameter changes by transforming the security parameter from a binary state (allowed/not allowed) to a controlled state with multiple encryption keys. Different encryption keys are assigned to different groups, and access is granted based on which key can decrypt the data. This resolves the contradiction by maintaining accessibility for authorized users while blocking unauthorized access through cryptographic control.
Solution Approach 2:
The patent implements local quality by assigning different encryption keys to different groups of users. Instead of a uniform access policy, each group receives a specific encryption key that grants access only to data encrypted with that key. This creates localized access control where different parts of the system (different user groups) have different access permissions, resolving the contradiction between general accessibility and specific security requirements.
2Reliability
If encryption keys are used to restrict access, then security is improved, but device complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the encryption key management into separate, independent keys for different user groups. Instead of a single complex access control system, multiple simple encryption keys are distributed to different groups. Each key independently controls access to its corresponding encrypted data, simplifying the overall system while maintaining high security through cryptographic division of access rights.
Data Source
AI summary
In some examples, a device receives a plurality of encryption keys from a secure storage of a management controller, where a first encryption key of the plurality of encryption keys is for site-wide access of information on removable storage media plugged into respective computers of a site, and a second encryption key of the plurality of encryption keys is to restrict access of information on removable storage media plugged into a subset of the computers. The device uses a given encryption key of the plurality of encryption keys to encrypt information written to or decrypt information read from a first removable storage medium plugged into a first computer of the computers, wherein the management controller is associated with and is separate from a processor of the first computer.


