Secure Key Management via Hardware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security systems are vulnerable to malware attacks, especially when the operating system is compromised, as they rely on central processing units and require frequent updates, leaving a window of vulnerability for data theft during processing and transmission.

Innovation Solution

A secondary device with a programmable hardware component and secure data storage, which generates and distributes encryption keys independently of the central processor, using a one-way communications link to ensure secure key management and bypass the CPU for secure data transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is processed and transmitted through the operating system and central processor, then data transmission functionality is achieved, but the system becomes vulnerable to malware attacks and data theft

Engineering Contradiction:
Improvedata securityVSAvoidmalware vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system separates data transmission functionality from the vulnerable operating system by implementing a dedicated hardware layer (secure enclave, trusted platform module, or separate secure processor) that handles encryption and decryption operations independently. This segmentation isolates sensitive cryptographic operations from malware-prone software environments, maintaining security while enabling data transmission.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary secure hardware component is introduced between the unencrypted data storage and the transmission channel. This intermediary performs encryption/decryption operations without exposing sensitive data to the operating system or potential malware, acting as a trusted mediator that protects data while enabling secure communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If software-based anti-virus mechanisms are used to detect and remove malware, then malware detection capability is provided, but a window of vulnerability exists between malware introduction and counter measure deployment

Engineering Contradiction:
Improvemalware protectionVSAvoidvulnerability window
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security measures are implemented in advance by embedding cryptographic protection at the hardware level before malware can compromise the system. Encryption keys are generated and stored securely in hardware, and data is encrypted before it can be accessed by potential malware, eliminating the vulnerability window that exists in software-based approaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces software-based security mechanisms with hardware-based cryptographic protection. Instead of relying on software anti-virus updates that leave time gaps, the system uses dedicated hardware security modules that provide continuous protection without requiring updates, substituting mechanical/hardware reliability for software vulnerability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If encryption is handled by the operating system to ensure data privacy, then encryption functionality is achieved, but the encryption can be compromised by preexisting malicious software

Engineering Contradiction:
Improveencryption securityVSAvoidsoftware-based encryption vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The encryption function is segmented from the operating system into a separate, dedicated hardware security module. This segmentation ensures that even if the operating system is compromised by malware, the encryption keys and cryptographic operations remain protected in the isolated hardware environment, maintaining encryption security independent of software integrity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware-based intermediary layer is positioned between the data and the transmission channel, performing encryption operations without involving the operating system. This intermediary protects cryptographic operations from software-based attacks while maintaining the necessary encryption functionality for data privacy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9419954B1Storing and transmitting sensitive data
Publication Date: 2016.08.16 LOCKHEED MARTIN CORP
  • US9419954B1 patent drawing
  • US9419954B1 patent drawing
  • US9419954B1 patent drawing

AI summary

A system for secure key management including a secondary device comprising a programmable hardware component and an associated secure data storage, wherein the secondary device comprises a one-way communications link to receive input unilaterally from a computing device, an encryption key generator to generate and store encryption keys on the secure data storage, and an encryption key distribution module to distribute encryption keys to one or more destinations on a computer network through a communications interface component, wherein the distribution is adapted to bypass a central processor of the computing device. A method is also provided.