Removable Storage TPM Interface for Secure Backup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current removable media devices lack a standardized and secure method to interface with Trusted Platform Modules (TPM) for secure data backup and restoration, leading to vulnerabilities in data access and protection, especially with the portability of devices increasing the risk of data loss or unauthorized access.

Innovation Solution

A system and apparatus that integrate a computer-readable mass storage device with a trusted platform interface module and cryptographic module, allowing secure communication with a TPM for encrypted password management and secure backup and restore operations, ensuring data access only on the system that created it.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is stored on removable media devices, then portability and accessibility are improved, but security and risk of unauthorized access deteriorate

Engineering Contradiction:
ImproveportabilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Trusted Platform Module (TPM) as an intermediary between the removable media device and the data protection mechanism. The TPM generates and manages cryptographic keys that are bound to the specific system, creating a mediator that ensures only the authorized system can access the encrypted data on the removable media, thus resolving the contradiction between portability and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If password encryption is used on removable media, then data protection is improved, but usability and data recovery deteriorate

Engineering Contradiction:
Improvedata protectionVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service authentication by automatically using the TPM-bound keys to decrypt data on the authorized system. The user does not need to manually enter passwords or perform authentication steps - the system automatically verifies trustworthiness through the TPM and decrypts the data seamlessly, thus improving usability while maintaining strong protection.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If standardized security interfaces are implemented, then compatibility and security consistency are improved, but device complexity increases

Engineering Contradiction:
ImprovecompatibilityVSAvoidinterface complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal TPM interface standard that is already widely supported across modern systems. By using this existing standardized interface, the solution achieves broad compatibility without adding significant complexity - the TPM can serve multiple security functions including key generation, encryption, and authentication across different platforms and removable media devices.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7330977B2Apparatus, system, and method for secure mass storage backup
Publication Date: 2008.02.12 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US7330977B2 patent drawing
  • US7330977B2 patent drawing
  • US7330977B2 patent drawing

AI summary

An apparatus for securely backing up data using a cryptographic module includes a mass storage device having a first accessible portion and a second encrypted portion. The mass storage device is initialized to only decrypt the encrypted portion on the system that first created the encrypted portion. The cryptographic module may be a Trusted Platform Module (TPM) based on specifications from the Trusted Computer Group. The mass storage device comprises a trusted platform interface module configured to communicate with the TPM. The system may include a motherboard having a TPM, and the mass storage device. The method in one embodiment comprises providing a computer readable mass storage device, initializing a password module, transmitting an encrypted password to the cryptographic module, authenticating the encrypted password, decrypting the encrypted password, transmitting the decrypted password to the computer readable medium, and decrypting the second encrypted portion using the decrypted password.