Secure Module Mediator for Encryption Key Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cryptographic systems face security vulnerabilities due to long encryption keys being difficult for users to remember, leading to reliance on shorter, less secure passwords, and fingerprint-based systems are insecure as fingerprints can be easily captured by intruders, compromising the entire system.
Innovation Solution
A decentralized security system that generates unique encryption keys locally using biometric data, such as fingerprints, and creates temporary passcodes that are difficult to compromise, ensuring enhanced security and privacy by preventing centralized points of vulnerability.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If long encryption keys are used, then security is improved, but ease of operation deteriorates because users cannot remember them
Solution Approach 1:
The patent introduces a secure module as an intermediary device that stores and manages encryption keys externally. This mediator handles the complexity of long encryption keys by providing a dedicated secure storage unit with a separate interface, allowing users to access encrypted data without directly handling or remembering the complex keys themselves.
2Ease of operation
If passwords are used to access computers containing encryption keys, then ease of operation is improved, but security deteriorates because passwords are easier to obtain
Solution Approach 1:
The secure module acts as an intermediary authentication layer between the user and the encryption keys. Instead of directly accessing computer passwords, users authenticate through the secure module's interface, which then provides authorized access to the encryption keys. This intermediary layer prevents direct exposure of both passwords and encryption keys to potential intruders.
3Ease of operation
If fingerprints are scanned to access computers, then ease of operation is improved, but security deteriorates because fingerprints can be captured by intruders
Solution Approach 1:
The secure module serves as an intermediary biometric authentication device that processes fingerprint scans locally. Rather than transmitting raw fingerprint data to computers for processing, the secure module handles the biometric verification internally and only provides access authorization. This intermediary approach maintains ease of biometric operation while preventing intruders from capturing usable fingerprint data.
4Ease of operation
If encryption keys are stored on computers, then ease of operation is improved, but security deteriorates because operating systems have security flaws
Solution Approach 1:
The patent segments the cryptographic system into two separate components: a general-purpose computer for data processing and a dedicated secure module for key storage. This segmentation isolates the encryption keys from the vulnerable operating system environment, placing them in a separate, hardened security domain with its own interface and protection mechanisms.
Solution Approach 2:
The secure module functions as an intermediary storage device that bridges the gap between data processing needs and security requirements. It provides controlled access to encryption keys through a secure interface, mediating between the untrusted general-purpose computer environment and the sensitive cryptographic materials, thereby protecting keys from OS-level security flaws.
Data Source
AI summary
In an embodiment a secure module is provided that provides access keys to an unsecured system. In an embodiment the secure module may generate passcodes and supply the passcodes to the unsecured system. In an embodiment the access keys are sent to the unsecured system after receiving the passcode from the unsecured system. In an embodiment, after authenticating the passcode, the secure module does not store the passcode in its memory. In an embodiment, the unsecured module requires the access key to execute a set of instructions or another entity. In an embodiment, the unsecured system does not store access keys. In an embodiment, the unsecured system erases the access key once the unsecured system no longer requires the access key. In an embodiment, the unsecured system receives a new passcode to replace the stored passcode after using the stored passcode. Each of these embodiments may be used separately.


