Removable Storage Encryption IC with Key Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data encryption and decryption methods for removable storage devices either require specialized internal circuitry, increasing cost and complexity, or rely on host OS software, making keys vulnerable to malware attacks.
Innovation Solution
An integrated circuit with an encryption/decryption engine that securely manages cryptographic operations, including generating device wrap keys and decrypting encrypted keys, without the need for specialized storage device circuitry, allowing secure data access based on user authentication and access privileges.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If specialized internal circuitry is added to the storage device for encryption, then data security is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces an integrated circuit as an intermediary component that handles encryption/decryption operations. This separate encryption module acts as a mediator between the storage device and host computer, performing cryptographic functions without requiring the storage device itself to have complex specialized circuitry. The integrated circuit contains the encryption engine and manages keys securely, thus improving data security while keeping the storage device relatively simple.
2Reliability
If specialized internal circuitry is added to the storage device for encryption, then data security is improved, but manufacturing cost increases
Solution Approach 1:
By using an integrated circuit as an intermediary, the patent separates the encryption function from the storage device manufacturing. The integrated circuit can be a standardized component produced separately and then incorporated into the storage device, reducing the need for expensive custom circuitry in each storage device. This approach maintains security while lowering manufacturing costs through component standardization.
Solution Approach 2:
The patent uses software-based encryption implementations that can be replicated across multiple devices without requiring unique hardware for each. The encryption algorithms and key management can be copied and deployed through the integrated circuit, providing secure encryption at lower per-unit costs compared to custom hardware solutions.
3Device complexity
If encryption is performed by host OS software, then device complexity is reduced, but key security deteriorates due to malware vulnerability
Solution Approach 1:
The integrated circuit serves as a secure intermediary that isolates key management from the host OS software environment. By moving key storage and cryptographic operations to a dedicated hardware component, the patent creates a security boundary that prevents malware on the host system from accessing encryption keys, thus maintaining key security while keeping the overall system architecture relatively simple.
Solution Approach 2:
The integrated circuit provides self-service security functions by independently managing key storage and encryption operations without relying on the host OS software. The encryption engine within the integrated circuit autonomously performs cryptographic operations and protects keys from external access, including malware, thereby ensuring key security without adding significant complexity to the storage device.
Data Source
AI summary
In an embodiment, an apparatus is provided that may include an integrated circuit to be removably communicatively coupled to at least one storage device. The integrated circuit of this embodiment may be capable of encrypting and/or and decrypting, based at least in part upon a first key, data to be, in at least in part, stored in and/or retrieved from, respectively, at least one region of the at least one storage device. The at least one region and a second key may be associated with at least one access privilege authorized, at least in part, by an administrator. The second key may be stored, at least in part, externally to the at least one storage device. The first key may be obtainable, at least in part, based, at least in part, upon at least one operation involving the second key. Of course, many alternatives, modifications, and variations are possible without departing from this embodiment.


