Secure Storage Encryption Key Segmentation for Autonomous IoT Reactivation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT systems face challenges in achieving autonomous reactivation and secure continuous operation without stable network connectivity, as existing security techniques require user intervention or network access to manage encryption keys, leading to potential data leakage and system delays.

Innovation Solution

An information processing device with a secure storage system that includes an access limit area for a first encryption key and a second encryption key, allowing trusted software to construct a common encryption key for setting up an encrypted file system accessible from any software, enabling autonomous reactivation and secure data protection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing encryption techniques are used, then information security is improved, but system autonomy and continuous operation are worsened due to requiring manager intervention and network connectivity

Engineering Contradiction:
Improveinformation securityVSAvoidautonomous reactivation
Core Design Contradiction:
ReliabilityVSExtent of automation

Solution Approach 1:

The patent pre-stores the first encryption key and second encryption key in the secure storage before any encryption operation occurs. The first encryption key is stored in the access limit area, and the second encryption key (encrypted by the first) is stored in the second encryption key keeping unit. This preliminary key preparation enables the system to perform autonomous encryption and decryption operations without requiring manager intervention or network connectivity at the time of data processing, thus resolving the contradiction between maintaining high information security and achieving system autonomy.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If existing encryption techniques are used, then information security is improved, but network dependency is worsened

Engineering Contradiction:
Improveinformation securityVSAvoidnetwork interruption impact
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements self-service by enabling the edge device to autonomously manage its own encryption keys and perform encryption/decryption operations locally. The secure storage contains both the first encryption key and the second encryption key (encrypted by the first), allowing the device to decrypt data and access encrypted areas without requiring network connection to a management server. This eliminates network dependency while maintaining information security, as the device serves itself rather than relying on external network resources.

Inventive Principle:
Principle #25Self-service

3Reliability

If manager intervention is required for key management, then security control is improved, but system response time is worsened

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary key storage and configuration during system setup, where the first encryption key is stored in the access limit area and the second encryption key is encrypted and stored in the second encryption key keeping unit. This preliminary action eliminates the need for real-time manager intervention during data processing operations, allowing the system to respond immediately to encryption and decryption needs without time loss to key management procedures.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If encrypted file system is made accessible from any software, then ease of operation is improved, but security risk is worsened

Engineering Contradiction:
ImproveaccessibilityVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the key management functionality into distinct components: the first encryption key is stored in the access limit area (accessible only to trusted software), while the second encryption key (encrypted by the first) is stored in the second encryption key keeping unit. This segmentation allows any software to access the encrypted area through the encrypted file system interface, while the actual decryption process requires the first encryption key which is protected in the access limit area. Thus, ease of operation is maintained for data access, while security is preserved through segmented key protection.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11336439B2Information processing device, information processing method, and recording medium
Publication Date: 2022.05.17 NEC CORP
  • US11336439B2 patent drawing
  • US11336439B2 patent drawing
  • US11336439B2 patent drawing

AI summary

An information processing device which includes: a secure storage accessible by only trusted software, in which a first encryption key keeping unit keeping a first encryption key is configured inside a access limit area; a second encryption key keeping unit keeping as a second encryption key; a setup processing activation unit acquiring the second encryption key from the second encryption key keeping unit in response to activation of a local device, and outputting the acquired second encryption key; and a software execution unit being executed as the trusted software, acquiring the second encryption key from the setup processing activation unit, acquiring the first encryption key from the first encryption key keeping unit together with acquisition of the second encryption key, constructing a common encryption key by using the first encryption key and second encryption key, and setting up an encrypted file system by using the constructed common encryption key.