Spatially-Bound Cryptographic Storage for Secure Data Transfer

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Sensitive digital information leakage from trusted offline labs occurs due to the ease with which portable storage devices can be taken outside secure environments, posing a significant risk of classified information exposure.

Innovation Solution

A method and system that establish a secure data storage mechanism by using multi-party computation policies and environmental beacons to intercept and encrypt data within a secure environment, ensuring that data can only be read or written if the multi-party policy is met, and utilizing a stationary beacon to authenticate storage devices and manage encryption keys, thereby preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If portable storage devices are used for data transfer, then ease of operation is improved, but security is worsened due to risk of unauthorized removal from secure environments

Engineering Contradiction:
Improveease of data transferVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs preliminary encryption of data on the portable storage device before it leaves the secure environment. The encryption keys are generated and applied in advance while the device is still within the trusted boundary, ensuring that even if the device is removed unauthorized, the data remains protected. This preliminary security action resolves the contradiction by maintaining ease of data transfer while preventing security breaches.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication system that acts as a mediator between the portable storage device and the secure environment. The authentication module on the storage device communicates with the secure environment through defined protocols, verifying the device's location and authorization status. This intermediary layer enables easy data transfer for authorized devices while blocking unauthorized access, thus resolving the security-ease of operation contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If data is encrypted to prevent unauthorized access, then security is improved, but ease of operation is worsened due to additional authentication requirements

Engineering Contradiction:
ImprovesecurityVSAvoidease of data access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The portable storage device incorporates self-service authentication capabilities, where the device automatically performs encryption and decryption operations using stored keys without requiring manual user intervention. The authentication module autonomously verifies the device's location relative to the secure environment and applies appropriate security measures. This self-service approach maintains security while minimizing the operational burden on users, as the encryption/decryption process occurs automatically in the background.

Inventive Principle:
Principle #25Self-service

3Reliability

If authentication systems are implemented to control access, then security is improved, but device complexity is worsened due to additional authentication components

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal authentication module that serves multiple functions: it performs encryption/decryption, verifies location relative to the secure environment, manages key storage, and controls data access. By consolidating these security functions into a single multi-functional component on the portable storage device, the system achieves high security without proportionally increasing complexity. The same hardware module handles various security tasks, reducing the need for separate dedicated components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11722299B1Spatially-bound cryptographic storage
Publication Date: 2023.08.08 PERSPECTA LABS INC
  • US11722299B1 patent drawing
  • US11722299B1 patent drawing
  • US11722299B1 patent drawing

AI summary

Embodiments of the present invention include a computer program product, a computer-implemented method, and a system, where program code executing on one or more processors (on a client) obtains, from a host within a secure environment, data stored on the host. To obtain the data, the processor(s) establishes a communications connection to a computing resource in the secure environment and authenticates to the computing resource to obtain a key. The processor(s) intercepts the data, encrypts the data, with the key, and stores the encrypted data on a buffer accessible to the client.