Secure Mobile Storage Device with Segmented Key Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile storage devices for secure data processing, such as key disks, fail to adequately prevent hackers from spying on and attacking sensitive data during transactions, particularly in e-payment and e-banking services, as they lack integration of application logic and network interface simulation capabilities.

Innovation Solution

A mobile storage device with a processing unit that performs both security and application processing, including data encryption and decryption, and simulates a network interface to establish direct connections with remote devices, enabling secure transaction processing and enhancing security by integrating application logic within the device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secret keys and digital certificates are stored in a data storage space under protection in existing mobile storage devices, then the possibility of copying digital certificate or identity information is prevented, but hackers can still spy on and attack sensitive data involved in transactions

Engineering Contradiction:
Improvesecurity of secret key storageVSAvoidhacker attacks on sensitive data
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the storage space into multiple isolated regions: a first storage space for secret keys and digital certificates, and a second storage space for application programs. This segmentation ensures that even if one space is compromised, the secret keys remain protected in the isolated first space, preventing hackers from accessing sensitive data through application program vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an interface as an intermediary layer between the protected first storage space and the external environment. This interface controls and monitors all access to secret keys and digital certificates, enabling secure communication while preventing direct hacker access to sensitive data stored in the first storage space.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated programs inside the device only provide application program interface (API) for external applications, then the secret key and digital certificate are protected from direct access, but the dedicated program has no association with external applications in view of application logic

Engineering Contradiction:
Improveprotection of secret key accessVSAvoidassociation with external applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The interface acts as an intermediary that enables association between the dedicated program and external applications through standardized API calls. The interface translates external application requests into operations that the dedicated program can execute, maintaining security while enabling versatile integration with various external applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The interface provides universal API capabilities that allow the dedicated program to work with multiple different external applications. By implementing standard interface protocols, the system achieves broad adaptability and versatility without compromising the security isolation of the first storage space.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If application programs are stored separately from secret keys in existing devices, then the secret key storage remains protected, but the device cannot establish direct network connections for secure transaction processing

Engineering Contradiction:
Improveisolation of secret key storageVSAvoiddirect network connection capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments functionality into distinct storage spaces while enabling integrated operation. The first storage space maintains isolated protection for secret keys, while the second storage space holds application programs that can establish direct network connections. This segmentation allows both security isolation and network operation capabilities to coexist effectively.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The interface serves as an intermediary that coordinates between the isolated first storage space and the network-facing application programs. It enables secure transaction processing by managing communication between the protected secret keys and the external network environment, allowing direct network connections while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2634703B1Removable storage device, and data processing system and method based on the device
Publication Date: 2018.02.21 CHINA UNIONPAY
  • EP2634703B1 patent drawingFigure 1~2a
  • EP2634703B1 patent drawingFigure 2b
  • EP2634703B1 patent drawingFigure 3

AI summary

The present invention relates to network security technology, and particularly relates to a mobile storage device for data processing in security, and a data processing system comprising the mobile storage device, and a data processing method using the data processing system. According to the present invention, the mobile storage device for data processing in security comprising: at least one memory for storing a secret key; an interface circuit; and a processing unit for communicating with a remote device via the interface circuit and performing security processing and application processing, the security processing including data encryption and decryption with the secret key. Compared with the prior art, the mobile storage device according to the embodiments of the present invention stores not only confidential information such as secret key and digital certificate but also applications for executing transaction processes, whereby providing security protection for the applications at the same level as the confidential information. In addition, where the mobile storage device has a capability of simulating a network interface, a client terminal, such as a personal computer, previously used for executing the applications now can function as a bridge connector between the mobile storage device and a remote server, and the packeting and unpacketing of the transaction data can be performed inside the mobile storage device. This greatly improves the security performance of the transaction processes.