Secure Key Generation via Media ID and User Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional encryption technologies use keys associated only with specific devices, which can compromise data security when the device is used, as protection is removed, and there is a need for a solution that generates a secure key belonging to both a device and a user to protect digital content privacy.

Innovation Solution

A secure key generating apparatus that calculates a unique media ID from a primitive ID and combines it with user authentication information to create a secure key, ensuring the key belongs to both the device and the user, and is generated in a trusted execution environment to prevent leakage of device and user information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a digital encryption key is associated only with a specific device, then the encryption can be implemented, but the protection is removed when the specific device is used

Engineering Contradiction:
Improvedata protectionVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges device identification (media ID) with user authentication information to generate a unified secure key. This combination ensures that both the device and user must be authorized for content access, resolving the contradiction by maintaining protection while enabling legitimate device usage through proper authentication.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure key is segmented into two independent components: device-specific media ID and user-specific authentication information. This segmentation allows the system to maintain strong protection while enabling ease of operation through separate authentication mechanisms that can be independently validated.

Inventive Principle:
Principle #1Segmentation

2Reliability

If user authentication information is required for key generation, then data protection is enhanced, but the complexity of the system increases

Engineering Contradiction:
Improvedata protectionVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a trusted execution environment as an intermediary component that handles the complex authentication and key generation processes. This mediator abstracts the complexity from the user interface while maintaining enhanced security through rigorous authentication protocols.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service authentication by automatically validating user credentials and generating secure keys without requiring manual intervention. The trusted execution environment autonomously manages the authentication process, reducing operational complexity while maintaining strong data protection.

Inventive Principle:
Principle #25Self-service

3Reliability

If a trusted execution environment is used to generate the secure key, then security against information leakage is improved, but the requirements for secure hardware and software increase

Engineering Contradiction:
Improvesecurity against leakageVSAvoidtrusted computing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary security setup by establishing a trusted execution environment before content storage and access operations. This advance security configuration ensures that all subsequent operations occur within a verified secure context, preventing information leakage while managing hardware and software requirements through proactive rather than reactive security measures.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9135417B2Apparatus for generating secure key using device and user authentication information
Publication Date: 2015.09.15 SAMSUNG ELECTRONICS CO LTD
  • US9135417B2 patent drawing
  • US9135417B2 patent drawing
  • US9135417B2 patent drawing

AI summary

A secure key generating apparatus comprising an ID calculating unit receiving a primitive ID from a first storage device and calculating a first media ID, (a unique identifier of the first storage device), from the first primitive ID; a user authentication information providing unit providing user authentication information for authenticating the current; and a secure key generating unit for generating a first Secure Key using both the first media ID and the first user's authentication information. The Secure Key is used to encrypt/decrypt content stored in the first storage device. The secure key generating unit generates a first different Secure Key using a second media ID of a second storage device, and generates a second different Secure Key using second user's user authentication information. Only the first Secure Key can be used to decrypt encrypted content stored in the first storage device that was encrypted using the first Secure Key.