Spatially-Bound Cryptographic Storage for Secure Data Transfer
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Sensitive digital information leakage from trusted offline labs occurs due to the ease with which portable storage devices can be taken outside secure environments, posing a significant risk of classified information exposure.
Innovation Solution
A method and system that establish a secure data storage mechanism by using multi-party computation policies and environmental beacons to intercept and encrypt data within a secure environment, ensuring that data can only be read or written if the multi-party policy is met, and utilizing a stationary beacon to authenticate storage devices and manage encryption keys, thereby preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If portable storage devices are used for data transfer, then ease of operation is improved, but security is worsened due to risk of unauthorized removal from secure environments
Solution Approach 1:
The system performs preliminary encryption of data on the portable storage device before it leaves the secure environment. The encryption keys are generated and applied in advance while the device is still within the trusted boundary, ensuring that even if the device is removed unauthorized, the data remains protected. This preliminary security action resolves the contradiction by maintaining ease of data transfer while preventing security breaches.
Solution Approach 2:
The patent introduces an intermediary authentication system that acts as a mediator between the portable storage device and the secure environment. The authentication module on the storage device communicates with the secure environment through defined protocols, verifying the device's location and authorization status. This intermediary layer enables easy data transfer for authorized devices while blocking unauthorized access, thus resolving the security-ease of operation contradiction.
2Reliability
If data is encrypted to prevent unauthorized access, then security is improved, but ease of operation is worsened due to additional authentication requirements
Solution Approach 1:
The portable storage device incorporates self-service authentication capabilities, where the device automatically performs encryption and decryption operations using stored keys without requiring manual user intervention. The authentication module autonomously verifies the device's location relative to the secure environment and applies appropriate security measures. This self-service approach maintains security while minimizing the operational burden on users, as the encryption/decryption process occurs automatically in the background.
3Reliability
If authentication systems are implemented to control access, then security is improved, but device complexity is worsened due to additional authentication components
Solution Approach 1:
The patent implements a universal authentication module that serves multiple functions: it performs encryption/decryption, verifies location relative to the secure environment, manages key storage, and controls data access. By consolidating these security functions into a single multi-functional component on the portable storage device, the system achieves high security without proportionally increasing complexity. The same hardware module handles various security tasks, reducing the need for separate dedicated components for each function.
Data Source
AI summary
Embodiments of the present invention include a computer program product, a computer-implemented method, and a system, where program code executing on one or more processors (on a client) obtains, from a host within a secure environment, data stored on the host. To obtain the data, the processor(s) establishes a communications connection to a computing resource in the secure environment and authenticates to the computing resource to obtain a key. The processor(s) intercepts the data, encrypts the data, with the key, and stores the encrypted data on a buffer accessible to the client.


