Self-Encrypting Module With Embedded Wireless Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current data security systems for portable memory storage devices rely on host computers for user authentication, making them susceptible to hacking and compromising encryption key security.

Innovation Solution

A self-encrypting data security system with a mobile device-based authentication method, using a radiofrequency transceiver for independent user authentication, where the authentication subsystem manages encryption keys without relying on host resources, ensuring secure storage and transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional encryption methods with separate authentication and encryption processes are used, then authentication flexibility is improved, but device complexity and vulnerability to attacks increase

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent combines the authentication subsystem and encryption subsystem into a single integrated security device. The authentication module and encryption module share common hardware resources including processor, memory, and communication interfaces, eliminating the need for separate authentication and encryption devices while maintaining security functionality.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security device is designed to perform multiple functions within a single system: authentication verification, key generation, encryption, and decryption operations. The authentication subsystem can verify multiple types of credentials (passwords, biometrics, tokens) while the encryption subsystem supports various encryption algorithms, providing universal security capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If data is encrypted before leaving the device, then data security is improved, but accessibility and usability deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The authentication subsystem acts as an intermediary between the user and the encryption subsystem. It verifies user credentials and manages authentication states, controlling access to decryption operations without exposing the encryption keys. This mediator approach maintains security while enabling authorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The encryption subsystem automatically performs encryption and decryption operations based on authentication status without requiring manual key management. The system self-manages the encryption keys and decryption processes, reducing user burden while maintaining security through automated key protection mechanisms.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication information is stored externally, then security against physical attacks is improved, but device complexity and attack surface increase

Engineering Contradiction:
Improveprotection against physical attacksVSAvoidattack surface
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication information storage is merged with the encryption key storage within the same secure hardware environment. Both authentication credentials and encryption keys are protected by the same physical security measures including secure element isolation and tamper detection, reducing the attack surface compared to separate external storage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security device creates a protected environment using secure element isolation and tamper detection mechanisms. The authentication subsystem operates in a secured hardware environment that detects and responds to physical tampering attempts, creating an inert atmosphere resistant to physical attacks while housing both authentication and encryption functions.

Inventive Principle:
Principle #39Inert atmosphere (Inert environment)

4Ease of operation

If manual authentication processes are used, then user control is improved, but processing time and productivity deteriorate

Engineering Contradiction:
Improveuser controlVSAvoidprocessing time
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The authentication subsystem performs preliminary verification of user credentials before encryption or decryption operations begin. By pre-validating authentication status and establishing security context in advance, the system enables faster subsequent data processing without compromising security controls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once authentication is established, the security device maintains continuous authenticated sessions for multiple encryption and decryption operations without requiring repeated authentication prompts. The authentication state persists, allowing continuous useful action in data protection operations while maintaining user control through initial authentication.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentEP4242902A2Self-encrypting module with embedded wireless user authentication
Publication Date: 2023.09.13 CLEVX LLC
  • EP4242902A2 patent drawingFigure 1
  • EP4242902A2 patent drawingFigure 2A
  • EP4242902A2 patent drawingFigure 2B

AI summary

Methods, systems, and computer programs are presented for a self-encrypting device (SED) incorporated into a host system. In one example, the host system includes a memory, a processor, a data channel in communication with the memory and the processor, and the SED. The SED comprises an authentication subsystem, a storage subsystem that stores encrypted data that is encrypted with an encryption key provided by the authentication subsystem, a radio frequency (RF) transceiver, and a data interface in electrical contact with the data channel. The data interface is locked from sending and receiving data until the SED is unlocked by the authentication subsystem with user-authentication information received via the RF transceiver.