Self-Encrypting Module With Embedded Wireless Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data security systems for portable memory storage devices rely on host computers for user authentication, making them susceptible to hacking and compromising encryption key security.
Innovation Solution
A self-encrypting data security system with a mobile device-based authentication method, using a radiofrequency transceiver for independent user authentication, where the authentication subsystem manages encryption keys without relying on host resources, ensuring secure storage and transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional encryption methods with separate authentication and encryption processes are used, then authentication flexibility is improved, but device complexity and vulnerability to attacks increase
Solution Approach 1:
The patent combines the authentication subsystem and encryption subsystem into a single integrated security device. The authentication module and encryption module share common hardware resources including processor, memory, and communication interfaces, eliminating the need for separate authentication and encryption devices while maintaining security functionality.
Solution Approach 2:
The security device is designed to perform multiple functions within a single system: authentication verification, key generation, encryption, and decryption operations. The authentication subsystem can verify multiple types of credentials (passwords, biometrics, tokens) while the encryption subsystem supports various encryption algorithms, providing universal security capabilities.
2Reliability
If data is encrypted before leaving the device, then data security is improved, but accessibility and usability deteriorate
Solution Approach 1:
The authentication subsystem acts as an intermediary between the user and the encryption subsystem. It verifies user credentials and manages authentication states, controlling access to decryption operations without exposing the encryption keys. This mediator approach maintains security while enabling authorized access.
Solution Approach 2:
The encryption subsystem automatically performs encryption and decryption operations based on authentication status without requiring manual key management. The system self-manages the encryption keys and decryption processes, reducing user burden while maintaining security through automated key protection mechanisms.
3Reliability
If authentication information is stored externally, then security against physical attacks is improved, but device complexity and attack surface increase
Solution Approach 1:
The authentication information storage is merged with the encryption key storage within the same secure hardware environment. Both authentication credentials and encryption keys are protected by the same physical security measures including secure element isolation and tamper detection, reducing the attack surface compared to separate external storage.
Solution Approach 2:
The security device creates a protected environment using secure element isolation and tamper detection mechanisms. The authentication subsystem operates in a secured hardware environment that detects and responds to physical tampering attempts, creating an inert atmosphere resistant to physical attacks while housing both authentication and encryption functions.
4Ease of operation
If manual authentication processes are used, then user control is improved, but processing time and productivity deteriorate
Solution Approach 1:
The authentication subsystem performs preliminary verification of user credentials before encryption or decryption operations begin. By pre-validating authentication status and establishing security context in advance, the system enables faster subsequent data processing without compromising security controls.
Solution Approach 2:
Once authentication is established, the security device maintains continuous authenticated sessions for multiple encryption and decryption operations without requiring repeated authentication prompts. The authentication state persists, allowing continuous useful action in data protection operations while maintaining user control through initial authentication.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
Methods, systems, and computer programs are presented for a self-encrypting device (SED) incorporated into a host system. In one example, the host system includes a memory, a processor, a data channel in communication with the memory and the processor, and the SED. The SED comprises an authentication subsystem, a storage subsystem that stores encrypted data that is encrypted with an encryption key provided by the authentication subsystem, a radio frequency (RF) transceiver, and a data interface in electrical contact with the data channel. The data interface is locked from sending and receiving data until the SED is unlocked by the authentication subsystem with user-authentication information received via the RF transceiver.