Authentication Subsystem for Portable Storage Encryption Key Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable memory storage devices face significant security challenges due to the vulnerability of stored encryption keys, which can be compromised when stored on the media itself, leading to potential data theft, despite existing authentication methods.

Innovation Solution

A data security system that employs an electronic authentication subsystem to verify user identification against an authentication key, retrieving an encryption key accessible only within the subsystem, allowing unencrypted communication between a host computer system and storage media, thereby keeping the encryption key secure and eliminating the need for it to be stored on the media.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the encryption key is stored on the storage media, then data can be encrypted and decrypted, but the encryption key becomes vulnerable to theft and unauthorized access

Engineering Contradiction:
Improvedata securityVSAvoidkey vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the encryption key from the storage media and places it in a separate authentication subsystem. The authentication subsystem contains the encryption key in encrypted form and only releases it after successful authentication, preventing the key from being stored on the media where it could be stolen.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an authentication subsystem as an intermediary between the user and the storage media. This subsystem acts as a mediator that controls access to the encryption key, requiring authentication before the key is released, thus adding a security layer that prevents direct access to the key.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the encryption key is not stored on the media, then security is improved, but the system complexity increases with additional authentication subsystems

Engineering Contradiction:
Improvedata securityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the authentication functionality and encryption key management into a single integrated authentication subsystem. This subsystem combines the encryption key storage, authentication logic, and key release mechanisms into one unified component, reducing overall system complexity compared to having separate distributed key management.

Inventive Principle:
Principle #5Merging (Combining)

3Ease of operation

If authentication is performed outside the subsystem, then user access is convenient, but the authentication key becomes accessible and vulnerable

Engineering Contradiction:
Improveuser accessVSAvoidkey exposure
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments the authentication process into two parts: user identification input (which can occur outside the subsystem for convenience) and authentication key verification (which occurs inside the protected subsystem). This segmentation allows convenient user interaction while keeping the sensitive authentication key verification secure within the subsystem boundaries.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9813416B2Data security system with encryption
Publication Date: 2017.11.07 CLEVX LLC
  • US9813416B2 patent drawing
  • US9813416B2 patent drawing
  • US9813416B2 patent drawing

AI summary

A data security system, and method of operation thereof, is provided that includes: an electronic authentication subsystem for verifying a user identification against an authentication key and for employing the authentication key for retrieving an encryption key, the authentication key only accessible from inside the electronic authentication subsystem, and the user identification supplied from outside the data security system to a receiver within the electronic authentication subsystem; and a storage subsystem employing the encryption key for allowing unencrypted communication through the storage subsystem between a host computer system and a storage media.